VYPR
Medium severity6.5NVD Advisory· Published Sep 1, 2026· Updated Sep 1, 2026

CVE-2026-72682

CVE-2026-72682

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Elastic/Kibanainferred2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <9.4.6

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.