PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72667 Elastic CVE debrief

A denial of service vulnerability via Excessive Allocation (CAPEC-130) in Kibana's Observability log analysis feature, with a CVSS score of 6.5 and MEDIUM severity, allows an authenticated user with minimal privileges to submit a specially crafted request, causing Kibana to perform an unbounded amount of concurrent work. This can exhaust the memory available to the Kibana process and make Kibana unavailable to all users until it is restarted. The severity of the outcome depends on the resources allocated to the deployment; on well-provisioned deployments, a single request may cause degraded performance and elevated memory pressure rather than a full outage, but the request is inexpensive to repeat. Users and administrators of Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5, particularly those with high-traffic or resource-intensive deployments, should prioritize applying security updates to prevent potential outages and performance degradation.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-02
Advisory published
2026-08-13
Advisory updated
2026-09-02

Who should care

Users and administrators of Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5, particularly those with high-traffic or resource-intensive deployments, should prioritize applying security updates to prevent potential outages and performance degradation.

Technical summary

A specially crafted request submitted by an authenticated user with minimal privileges to Kibana's Observability log analysis feature causes Kibana to perform an unbounded amount of concurrent work, leading to a denial of service via Excessive Allocation. This can exhaust the memory available to the Kibana process and make Kibana unavailable to all users until it is restarted. The vulnerability affects Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5. Implementing compensating controls, such as monitoring Kibana's memory usage and request load, can help mitigate the risk. Restricting access to Kibana's Observability log analysis feature can also minimize the attack surface. Upgrading to Kibana version 8.19.21 or 9.4.6, or later, if available, is recommended. Review and apply vendor-provided security updates for Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5. Consider these updates as part of a comprehensive defensive strategy to address potential outages and performance degradation in high-traffic or resource-intensive deployments. The vulnerability has a CVSS score of 6.5 and MEDIUM severity, emphasizing the need for prompt attention to prevent potential outages and performance degradation in Kibana deployments, especially those with high-traffic or resource-intensive configurations. Kibana's Observability log analysis feature is susceptible to this issue, and users should focus on applying security updates and implementing compensating controls to minimize risk. The vulnerability's impact can vary based on the resources allocated to the Kibana deployment, with well-provisioned deployments potentially experiencing degraded performance and elevated memory pressure rather than a full outage. However, the request is inexpensive to repeat, which can exacerbate the vulnerability's impact over time if not addressed. Therefore, a proactive approach to applying security updates and enhancing defensive measures is crucial for Kibana users to mitigate the risk of denial of service via Excessive Allocation effectively. This involves not only technical measures but also ensuring that the necessary monitoring and incident response strategies are in place to address

Defensive priority

Medium-severity denial of service vulnerability in Kibana's Observability log analysis feature requires prompt attention to prevent potential outages.

Recommended defensive actions

  • Review and apply vendor-provided security updates for Kibana versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5.
  • Implement compensating controls, such as monitoring Kibana's memory usage and request load.
  • Restrict access to Kibana's Observability log analysis feature to minimize the attack surface.
  • Consider upgrading to Kibana version 8.19.21 or 9.4.6, or later, if available.
  • Monitor Kibana deployments for excessive memory usage and request load.
  • Perform regular security audits to identify potential vulnerabilities.
  • Track changes to Kibana configurations and monitor for suspicious activity.

Evidence notes

The CVE record indicates a denial of service vulnerability via Excessive Allocation in Kibana's Observability log analysis feature, with a CVSS score of 6.5 and MEDIUM severity. An authenticated user with minimal privileges can submit a specially crafted request to cause Kibana to perform an unbounded amount of concurrent work, exhausting memory and making Kibana unavailable until restarted.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72667 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72667

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72667 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72667

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-98/389516

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.