Junglewise Threat Intelligence

CVE-2026-72682: Elastic Kibana resource exhaustion denial of service in Agent Builder

CVE-2026-72682 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is an analytics and visualization platform used to display data from Elasticsearch. An authenticated user with low-level Agent Builder privileges can submit a specially crafted request that causes Kibana to consume unlimited memory, crashing the process and making the service unavailable to all users.

Technical details

The vulnerability is an unmitigated resource allocation issue (CWE-770) in the Agent Builder feature introduced in Kibana 9.3.0. An authenticated attacker with read-level Agent Builder privileges can craft a malicious request that triggers unbounded memory consumption, leading to denial of service through process termination. Attack requires network access and valid authentication with the specified role. The issue is resolved in Kibana 9.4.6; users on 8.x releases are not affected as the Agent Builder feature is absent in that line.

Affected products

  • Elastic Kibana 9.3.0 through 9.4.5

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Kibana 9.4.6

References

Related threats