Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.
Published: 2026-09-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated user with low-level privileges to send a crafted request that causes Kibana to allocate an unbounded amount of memory, which can exhaust system resources and make the service unavailable to all users. This results in a denial of service through excessive resource consumption (CWE-770).

Affected Systems

Elastic Kibana is affected. The exact product version was not provided in the input, but the advisory indicates that versions before the security update contain the flaw.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. No EPSS score is available, suggesting insufficient data to quantify exploitation probability. The vulnerability is not listed in CISA KEV, so no evidence of active exploitation is known. The attack vector requires authentication with low-level privileges, and the exploit depends on the ability to submit a specially crafted request to Kibana.

Generated by OpenCVE AI on September 3, 2026 at 10:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update that addresses the resource allocation flaw
  • Limit access to Kibana for users with low-level privileges or disable the feature that processes the vulnerable request
  • Monitor memory usage and system performance to detect abnormal resource consumption during Kibana operation

Generated by OpenCVE AI on September 3, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.
Title Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:11.337Z

Reserved: 2026-08-24T21:13:45.972Z

Link: CVE-2026-78586

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:09.457Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:40.063

Modified: 2026-09-03T13:43:50.137

Link: CVE-2026-78586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling