Allocation of Resources Without Limits or Throttling in Kibana - CVE-2026-72651
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the alerting feature when handling a specially crafted malformed payload. A remote user can submit a specially crafted malformed payload to cause a denial of service.
A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.