PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72653 Elastic CVE debrief

CVE-2026-72653 is an Allocation of Resources Without Limits or Throttling (CWE-770) vulnerability in Kibana that can lead to denial of service via Excessive Allocation (CAPEC-130). The vulnerability was published on 2026-08-13T20:17:25.513Z and has not been modified since then. The NVD entry is currently Analyzed. Users of Elastic Kibana, especially those with maintenance window management privileges, should verify their Kibana version and apply security updates to prevent denial of service. Additionally, security teams and IT administrators responsible for Kibana deployments should be aware of the vulnerability and take necessary precautions. The CVE record was published on 2026-08-13T20:17:25.513Z and has not been modified since then. The NVD entry is currently Analyzed. Kibana becomes unresponsive for all users and does not recover without manual intervention.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-02
Advisory published
2026-08-13
Advisory updated
2026-09-02

Who should care

Users of Elastic Kibana, especially those with maintenance window management privileges, should verify their Kibana version and apply security updates to prevent denial of service. Additionally, security teams and IT administrators responsible for Kibana deployments should be aware of the vulnerability and take necessary precautions.

Technical summary

CVE-2026-72653 is an Allocation of Resources Without Limits or Throttling (CWE-770) vulnerability in Kibana that can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with maintenance window management privileges can submit a specially crafted payload, causing the Kibana process to consume excessive resources, making it unresponsive for all users. The vulnerability affects Kibana versions 8.12.0 to 8.19.19, 9.0.0 to 9.3.8, and 9.4.0 to 9.4.4. To mitigate the vulnerability, users should verify their Kibana version and apply security updates (ESA-2026-108). Additionally, implementing compensating controls to limit resource allocation and monitoring Kibana process for excessive resource consumption can help prevent denial of service.

Defensive priority

Authenticated users with maintenance window management privileges could cause Kibana denial of service via excessive resource allocation; verify Kibana version and restrict access.

Recommended defensive actions

  • Verify Kibana version is within affected ranges (8.12.0 to 8.19.19, 9.0.0 to 9.3.8, 9.4.0 to 9.4.4) and restrict access to maintenance window management.
  • Implement compensating controls to limit resource allocation and monitor Kibana process for excessive resource consumption.
  • Apply vendor-provided security updates (ESA-2026-108) to Kibana.
  • Review Kibana logs for excessive resource consumption.
  • Monitor system performance for potential denial of service.
  • Conduct regular security audits to identify potential vulnerabilities.
  • Establish incident response plan in case of denial of service.

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page supports Kibana vulnerability; verify affected versions 8.12.0 to 8.19.19, 9.0.0 to 9.3.8, and 9.4.0 to 9.4.4. Additional verification steps include reviewing Kibana logs for excessive resource consumption and monitoring system performance for potential denial of service.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72653 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72653

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72653 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72653

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-108/389514

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.