AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72651

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Kibana is vulnerable to a denial of service due to improper resource allocation, allowing an authenticated user with read-only privileges to exploit this flaw by submitting a specially crafted payload. This can lead to excessive resource consumption, rendering the Kibana instance unable to serve requests for all users until the process is restarted. Organizations using Kibana, particularly those with user roles that include read-only access to alerting features, should prioritize addressing this vulnerability to maintain service availability.

CVE
CVE-2026-72651
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%

Original NVD Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.