CVE-2026-72674
Last modified
CVE-2026-72674 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated before it was used to assemble the response for each matching document. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated before it was used to assemble the response for each matching document. A single crafted request could therefore make Kibana build a response far larger than the data it was derived from, and the resulting processing and memory pressure exhausts the resources of the Kibana instance.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 9.3.0, < 9.3.8 |
| Elastic | Kibana | >= 9.4.0, < 9.4.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-72674?
How severe is CVE-2026-72674?
How do I fix CVE-2026-72674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72669The state that Kibana stores for an Observability Onboarding…7.6
- CVE-2026-7267A flaw has been found in SourceCodester Pizzafy Ecommerce Sy…6.3
- CVE-2026-72670A lower privileged user who holds only the privilege to read…6.5
- CVE-2026-72671A Kibana Machine Learning capability that removes a saved ob…4.3
- CVE-2026-72672The Elastic Security capability that suggests existing field…7.7
- CVE-2026-72673Incorrect Authorization (CWE-863) in Kibana can lead to unau…5.4
- CVE-2026-72675Missing Authorization (CWE-862) in Kibana can lead to cross-…7.1
- CVE-2026-72676Improper Control of Generation of Code ('Code Injection') (C…9.1
- CVE-2026-72677Relative Path Traversal (CWE-23) in Kibana can lead to the u…7.3
- CVE-2026-72678Elasticsearch does not validate a size value taken from a us…6.5
- CVE-2026-72679Elasticsearch does not apply its configurable input length r…6.5
- CVE-2026-7268A vulnerability has been found in SourceCodester Pizzafy Eco…6.3
Are you affected by CVE-2026-72674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
