CVE-2026-72651: Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72651?
The severity of CVE-2026-72651 is medium with a score of 6.5.
How do I fix CVE-2026-72651?
To fix CVE-2026-72651, update Kibana to a version that addresses this vulnerability.
What type of attack is associated with CVE-2026-72651?
CVE-2026-72651 is associated with a denial of service attack.
Who is affected by CVE-2026-72651?
Authenticated users with read-only privileges to the alerting feature in Kibana are affected by CVE-2026-72651.
What causes the vulnerability in CVE-2026-72651?
CVE-2026-72651 is caused by the allocation of resources without limits or throttling in Kibana.