CVE-2026-72682: Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with only low, read-level Agent Builder privileges can exploit it. No user interaction is required.
What is the impact on a vulnerable Kibana instance?
A specially crafted request can drive unbounded memory consumption, terminate the Kibana process, and deny service to all users of that instance.
What access should be reviewed while remediation is pending?
Review which accounts have Agent Builder privileges, including read-level access, because that level is sufficient to trigger the denial of service.