CVE-2026-78586

Summary

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.

Affected Software

VendorProductVersion RangeStatus
ElasticKibana8.0.0 <= 8.19.15affected
ElasticKibana9.0.0 <= 9.3.4affected
ElasticKibana9.4.0 <= 9.4.1affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References