CVE-2026-72653: Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72653?
The severity of CVE-2026-72653 is medium with a score of 6.5.
How does CVE-2026-72653 affect Kibana?
CVE-2026-72653 affects Kibana by allowing authenticated users to submit malformed payloads, potentially leading to a denial of service.
Who is impacted by CVE-2026-72653?
Users of Kibana who have permissions to manage maintenance windows are impacted by CVE-2026-72653.
How do I fix CVE-2026-72653?
To fix CVE-2026-72653, update to the latest version of Kibana that addresses this vulnerability.
What kind of attack does CVE-2026-72653 represent?
CVE-2026-72653 represents a denial-of-service attack due to the allocation of resources without limits or throttling.