CVE-2026-72628: Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service

Published Sep 1, 2026
·
Updated

Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.

Affected Software

1 affected component
Elastic Kibana

Event History

Sep 1, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user with Streams management privileges can exploit it by supplying specially crafted highly compressed content. Unauthenticated users and users without those privileges are not identified as able to trigger the issue.

2

What is the operational impact if exploitation succeeds?

The crafted content can expand during processing and exhaust Kibana's available memory. The host terminates the Kibana process, leaving Kibana unavailable to all users until the service is restarted.

3

What can be done if patching cannot be performed immediately?

Restrict Streams management privileges to trusted users, since those privileges are required to supply the malicious content. Monitor Kibana availability and be prepared to restart the service if the process is terminated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203