Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Elastic Kibana allows an authenticated user with read‑only access to the alerting feature to submit a specially crafted payload that causes the Kibana process to allocate resources without limits or throttling. The resulting resource exhaustion can prevent Kibana from serving requests for any user until the process is restarted, effectively denying service to all stakeholders. This vulnerability is classified as CWE-770, highlighting an unbounded resource allocation weakness.

Affected Systems

Elastic Kibana versions 8.19.20 and 9.4.5 are vulnerable. Only users who can access the alerting feature with read‑only privileges can trigger the attack, but any user affected by the resulting denial of service will experience the impact.

Risk and Exploitability

The vulnerability receives a CVSS score of 6.5, indicating a moderate severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet reported. However, the attack vector requires authentication; thus, internal attackers or compromised user accounts pose a realistic threat. A single malicious request is sufficient to consume excessive resources and leave the Kibana instance unavailable until a restart occurs.

Generated by OpenCVE AI on August 13, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Elastic Kibana to any fixed release that addresses the unbounded allocation issue
  • Restrict or disable the alerting feature for users with only read‑only privileges, or remove their access through role management
  • Configure process or container limits and enable request throttling to cap resource usage during unexpected spikes

Generated by OpenCVE AI on August 13, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.
Title Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:30:10.213Z

Reserved: 2026-08-10T11:17:38.893Z

Link: CVE-2026-72651

cve-icon Vulnrichment

Updated: 2026-08-13T20:30:06.722Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:25.393

Modified: 2026-08-13T21:18:10.137

Link: CVE-2026-72651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling