Allocation of Resources Without Limits or Throttling in Kibana - CVE-2026-72659
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the Timelion visualization feature when processing a specially crafted, malformed payload. A remote user can submit a specially crafted, malformed payload to cause a denial of service.
Kibana becomes unavailable until the service is restarted.