Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user who is authorized to manage maintenance windows can submit a specially crafted, malformed payload that forces Kibana to consume excessive resources. The process becomes unresponsive for all users and does not recover until manual intervention is performed, effectively denying service to the entire Kibana instance.

Affected Systems

The vulnerability affects the Elastic Kibana product. The advisory does not list specific version numbers, so any Kibana installation that accepts maintenance window configurations is potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity attack. EPSS data is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting no widely known public exploitation. The attack requires legitimate credentials with maintenance window privileges, limiting the threat to insiders or compromised accounts, but once the permission boundary is crossed the system can be taken offline.

Generated by OpenCVE AI on August 13, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Elastic Security Update ESA-2026-108 for Kibana to enforce resource limits and prevent excessive allocation.
  • Restrict maintenance window configuration privileges to a minimal set of trusted accounts, ensuring only necessary users can submit maintenance windows.
  • Monitor Kibana resource consumption and configure alerting to detect excessive memory or CPU usage, and plan manual reset procedures if exploitation occurs.

Generated by OpenCVE AI on August 13, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.
Title Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:29:57.793Z

Reserved: 2026-08-10T11:17:38.893Z

Link: CVE-2026-72653

cve-icon Vulnrichment

Updated: 2026-08-13T20:29:54.232Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:25.513

Modified: 2026-08-13T21:18:10.240

Link: CVE-2026-72653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:30:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling