Allocation of Resources Without Limits or Throttling in Kibana - CVE-2026-72653
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the maintenance windows management functionality when processing a specially crafted, malformed payload. A remote user can submit a specially crafted, malformed payload to cause a denial of service.
Kibana becomes unresponsive for all users and does not recover without manual intervention.