PatchSiren cyber security CVE debrief
CVE-2026-72653 Elastic CVE debrief
CVE-2026-72653 is an Allocation of Resources Without Limits or Throttling (CWE-770) vulnerability in Kibana that can lead to denial of service via Excessive Allocation (CAPEC-130). The vulnerability was published on 2026-08-13T20:17:25.513Z and has not been modified since then. The NVD entry is currently Analyzed. Users of Elastic Kibana, especially those with maintenance window management privileges, should verify their Kibana version and apply security updates to prevent denial of service. Additionally, security teams and IT administrators responsible for Kibana deployments should be aware of the vulnerability and take necessary precautions. The CVE record was published on 2026-08-13T20:17:25.513Z and has not been modified since then. The NVD entry is currently Analyzed. Kibana becomes unresponsive for all users and does not recover without manual intervention.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-02
Who should care
Users of Elastic Kibana, especially those with maintenance window management privileges, should verify their Kibana version and apply security updates to prevent denial of service. Additionally, security teams and IT administrators responsible for Kibana deployments should be aware of the vulnerability and take necessary precautions.
Technical summary
CVE-2026-72653 is an Allocation of Resources Without Limits or Throttling (CWE-770) vulnerability in Kibana that can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with maintenance window management privileges can submit a specially crafted payload, causing the Kibana process to consume excessive resources, making it unresponsive for all users. The vulnerability affects Kibana versions 8.12.0 to 8.19.19, 9.0.0 to 9.3.8, and 9.4.0 to 9.4.4. To mitigate the vulnerability, users should verify their Kibana version and apply security updates (ESA-2026-108). Additionally, implementing compensating controls to limit resource allocation and monitoring Kibana process for excessive resource consumption can help prevent denial of service.
Defensive priority
Authenticated users with maintenance window management privileges could cause Kibana denial of service via excessive resource allocation; verify Kibana version and restrict access.
Recommended defensive actions
- Verify Kibana version is within affected ranges (8.12.0 to 8.19.19, 9.0.0 to 9.3.8, 9.4.0 to 9.4.4) and restrict access to maintenance window management.
- Implement compensating controls to limit resource allocation and monitor Kibana process for excessive resource consumption.
- Apply vendor-provided security updates (ESA-2026-108) to Kibana.
- Review Kibana logs for excessive resource consumption.
- Monitor system performance for potential denial of service.
- Conduct regular security audits to identify potential vulnerabilities.
- Establish incident response plan in case of denial of service.
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page supports Kibana vulnerability; verify affected versions 8.12.0 to 8.19.19, 9.0.0 to 9.3.8, and 9.4.0 to 9.4.4. Additional verification steps include reviewing Kibana logs for excessive resource consumption and monitoring system performance for potential denial of service.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72653 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72653
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72653 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72653
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-108/389514
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.