CVE-2026-72628

Summary

Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.

Affected Software

VendorProductVersion RangeStatus
ElasticKibana8.19.0 <= 8.19.20affected
ElasticKibana9.0.0 <= 9.4.5affected
ElasticKibana9.5.0 <= 9.5.1affected

Weaknesses

  • CWE-409: CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References