Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Kibana is vulnerable to excessive allocation of resources when an authenticated user submits a crafted request. This flaw, a classic instance of allocation without limits or throttling, can drain system memory or CPU, potentially rendering the application unavailable to legitimate users. The weakness is classified as CWE-770 and is noted to fall under the CAPEC-130 category of excessive allocation.

Affected Systems

The affected software is Elastic's Kibana product. No specific product versions are listed in the publicly available data, so the scope applies broadly to all Kibana installations until a patch is deployed.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. Because the flaw requires authentication, threat actors must have valid account credentials, but no additional prerequisites are highlighted in the description. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet confirmed. Nonetheless, an attacker who can log in can trigger the denial of service by overloading system resources.

Generated by OpenCVE AI on September 2, 2026 at 01:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Kibana to a patched version that addresses the resource allocation issue.
  • If a patch is unavailable, restrict Kibana access to a tightly controlled set of trusted users and consider implementing application‑level throttling or rate limits on request handling.
  • Apply network‑level controls, such as web‑application firewalls or load‑balancers, to detect and mitigate unusually high resource consumption patterns.

Generated by OpenCVE AI on September 2, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
Title Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:38:09.615Z

Reserved: 2026-08-10T11:17:38.893Z

Link: CVE-2026-72652

cve-icon Vulnrichment

Updated: 2026-09-01T19:38:07.020Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:16.970

Modified: 2026-09-02T14:22:27.283

Link: CVE-2026-72652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:45:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling