SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72628

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana is vulnerable to a denial-of-service attack due to improper handling of highly compressed data, allowing an authenticated user with Streams management privileges to submit specially crafted content that significantly increases memory allocation. This can lead to the termination of the Kibana process, rendering the service unavailable until it is manually restarted. Organizations using Kibana, especially those with user roles that include Streams management, should prioritize addressing this vulnerability to prevent service disruptions.

CVE
CVE-2026-72628
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.

Related CVEs

Other vulnerabilities affecting the same vendor(s)