CVE-2026-72659: Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before use. Processing the request causes unbounded memory growth in the Kibana process, which is terminated by the host once available memory is exhausted. Kibana then becomes unavailable to all users until the service is restarted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72659?
The severity of CVE-2026-72659 is rated as medium with a score of 6.5.
How do I fix CVE-2026-72659?
To fix CVE-2026-72659, update to the latest version of Kibana where the vulnerability is addressed.
What type of vulnerability is CVE-2026-72659?
CVE-2026-72659 is a resource allocation vulnerability that can lead to denial of service.
Who is affected by CVE-2026-72659?
Authenticated users with low-privileged access in Kibana can exploit CVE-2026-72659.
What can happen if CVE-2026-72659 is exploited?
Exploitation of CVE-2026-72659 can lead to a denial of service by overwhelming Kibana services.