Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Allocation of resources without limits in Elastic Kibana can cause excessive memory consumption when an authenticated user with low read-level Agent Builder privileges submits a crafted request. The request forces Kibana to allocate unbounded memory, causing the process to crash and denying service to all users of the instance.

Affected Systems

The vulnerability affects Elastic Kibana. No specific product versions are listed in the provided data, so all installed instances of Kibana are potentially impacted until an update is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not available and the issue is not listed in CISA KEV. Attackers must be authenticated and possess Agent Builder privileges, which limits the range of attackers but still allows denial of service if exploitation succeeds. Given the lack of exploit data, the likelihood remains uncertain but the potential impact warrants prompt mitigation.

Generated by OpenCVE AI on September 2, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Kibana release or apply the documented security update for version 9.4.6.
  • Revoke or reduce Agent Builder privileges for users who do not require them, limiting their ability to submit arbitrary requests.
  • Configure operating‑system–level memory limits or resource quotas for the Kibana process and set up monitoring and alerting for abnormal memory usage.

Generated by OpenCVE AI on September 2, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.
Title Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:38:37.348Z

Reserved: 2026-08-10T11:17:58.730Z

Link: CVE-2026-72682

cve-icon Vulnrichment

Updated: 2026-09-01T19:38:34.716Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T20:17:17.227

Modified: 2026-09-01T21:05:31.423

Link: CVE-2026-72682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T00:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling