PatchSiren cyber security CVE debrief
CVE-2026-72667 Elastic CVE debrief
A denial of service vulnerability via Excessive Allocation (CAPEC-130) in Kibana's Observability log analysis feature, with a CVSS score of 6.5 and MEDIUM severity, allows an authenticated user with minimal privileges to submit a specially crafted request, causing Kibana to perform an unbounded amount of concurrent work. This can exhaust the memory available to the Kibana process and make Kibana unavailable to all users until it is restarted. The severity of the outcome depends on the resources allocated to the deployment; on well-provisioned deployments, a single request may cause degraded performance and elevated memory pressure rather than a full outage, but the request is inexpensive to repeat. Users and administrators of Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5, particularly those with high-traffic or resource-intensive deployments, should prioritize applying security updates to prevent potential outages and performance degradation.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-02
Who should care
Users and administrators of Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5, particularly those with high-traffic or resource-intensive deployments, should prioritize applying security updates to prevent potential outages and performance degradation.
Technical summary
A specially crafted request submitted by an authenticated user with minimal privileges to Kibana's Observability log analysis feature causes Kibana to perform an unbounded amount of concurrent work, leading to a denial of service via Excessive Allocation. This can exhaust the memory available to the Kibana process and make Kibana unavailable to all users until it is restarted. The vulnerability affects Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5. Implementing compensating controls, such as monitoring Kibana's memory usage and request load, can help mitigate the risk. Restricting access to Kibana's Observability log analysis feature can also minimize the attack surface. Upgrading to Kibana version 8.19.21 or 9.4.6, or later, if available, is recommended. Review and apply vendor-provided security updates for Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5. Consider these updates as part of a comprehensive defensive strategy to address potential outages and performance degradation in high-traffic or resource-intensive deployments. The vulnerability has a CVSS score of 6.5 and MEDIUM severity, emphasizing the need for prompt attention to prevent potential outages and performance degradation in Kibana deployments, especially those with high-traffic or resource-intensive configurations. Kibana's Observability log analysis feature is susceptible to this issue, and users should focus on applying security updates and implementing compensating controls to minimize risk. The vulnerability's impact can vary based on the resources allocated to the Kibana deployment, with well-provisioned deployments potentially experiencing degraded performance and elevated memory pressure rather than a full outage. However, the request is inexpensive to repeat, which can exacerbate the vulnerability's impact over time if not addressed. Therefore, a proactive approach to applying security updates and enhancing defensive measures is crucial for Kibana users to mitigate the risk of denial of service via Excessive Allocation effectively. This involves not only technical measures but also ensuring that the necessary monitoring and incident response strategies are in place to address
Defensive priority
Medium-severity denial of service vulnerability in Kibana's Observability log analysis feature requires prompt attention to prevent potential outages.
Recommended defensive actions
- Review and apply vendor-provided security updates for Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5.
- Implement compensating controls, such as monitoring Kibana's memory usage and request load.
- Restrict access to Kibana's Observability log analysis feature to minimize the attack surface.
- Consider upgrading to Kibana version 8.19.21 or 9.4.6, or later, if available.
- Monitor Kibana deployments for excessive memory usage and request load.
- Perform regular security audits to identify potential vulnerabilities.
- Track changes to Kibana configurations and monitor for suspicious activity.
Evidence notes
The CVE record indicates a denial of service vulnerability via Excessive Allocation in Kibana's Observability log analysis feature, with a CVSS score of 6.5 and MEDIUM severity. An authenticated user with minimal privileges can submit a specially crafted request to cause Kibana to perform an unbounded amount of concurrent work, exhausting memory and making Kibana unavailable until restarted.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72667 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72667
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72667 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72667
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-98/389516
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.