Junglewise Threat Intelligence

CVE-2026-72652: Elastic Kibana denial of service via resource exhaustion in Timeline

CVE-2026-72652 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a visualization and analytics tool used to explore data in Elasticsearch, contains a resource exhaustion vulnerability in its Timeline feature. An authenticated user can craft a malicious request that consumes excessive system resources, causing Kibana to become unresponsive and unavailable to legitimate users. This impacts operational visibility into critical infrastructure and data.

Technical details

The vulnerability is a resource allocation flaw (CWE-770) in Kibana's Timeline feature that allows unthrottled resource consumption. An authenticated attacker can submit a specially crafted request that triggers excessive memory or CPU allocation, leading to denial of service (CAPEC-130). The attack requires valid Kibana credentials and network access to the Timeline API. Exploitation renders Kibana unavailable until the offending process is terminated or the service is restarted. The issue is patched in Kibana versions 8.19.19 and 9.3.5; all versions of 8.x through 8.19.18 and 9.x through 9.3.4 are affected.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.18, 9.0.0 to 9.3.4

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Kibana 8.19.19 and 9.3.5

References

Related threats