CVE-2026-72674
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-72674 is a Denial of Service vulnerability in Elastic Kibana caused by Allocation of Resources Without Limits or Throttling (CWE-770) in the Kibana Playground for RAG (Retrieval-Augmented Generation) feature. A user-supplied list of document fields is neither bounded in length nor de-duplicated before being used to assemble responses, allowing a single crafted request to trigger excessive memory and processing consumption. Affected versions are Kibana 9.3.0 through 9.3.7 and 9.4.0 through 9.4.3. It was published on August 13, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in Kibana's Playground for RAG feature. When a user submits a request to this feature, the list of document fields provided is passed directly into response assembly logic without any length cap or deduplication step, enabling an amplification effect where the resulting response can be orders of magnitude larger than the source data. Exploitation requires only a network-accessible Kibana instance and a low-privileged authenticated account with access to the Playground for RAG feature; no special configuration or chaining is needed. The attack pattern aligns with CAPEC-130 (Excessive Allocation) (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation causes the targeted Kibana instance to exhaust its memory and CPU resources, resulting in a crash or sustained unresponsiveness — a complete availability impact. There is no confidentiality or integrity impact, as the vulnerability does not expose data or allow modification of content. The scope is limited to the Kibana instance itself, but loss of Kibana availability can disrupt observability, security monitoring, and data analytics workflows that depend on it (GitHub Advisory, Elastic Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as not automatable, reflecting the requirement for authenticated access. The EPSS score is approximately 0.289%, placing it in the 22nd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Kibana instances running versions 9.3.0–9.3.7 or 9.4.0–9.4.3 that are network-accessible and have the Playground for RAG feature enabled.
  2. Authentication: Obtain or use low-privileged credentials with access to the Kibana Playground for RAG feature.
  3. Craft malicious request: Construct an API or UI request to the Kibana Playground for RAG endpoint that includes an extremely large, highly duplicated list of document field names in the user-supplied fields parameter.
  4. Submit request: Send the crafted request to the Kibana instance. The server will process the unbounded field list without deduplication, assembling a response far larger than the underlying data.
  5. Resource exhaustion: The excessive memory allocation and processing load causes Kibana to become unresponsive or crash, achieving denial of service (GitHub Advisory, Elastic Advisory).

Indicators of compromise

  • Network: Repeated or anomalous HTTP requests to Kibana's Playground for RAG API endpoint from a single source IP, particularly with unusually large request payloads.
  • Logs: Kibana server logs showing out-of-memory errors, heap exhaustion warnings, or abrupt process restarts; elevated response times or timeouts on RAG Playground endpoints.
  • Process: Sudden spike in Kibana Node.js process memory consumption (heap usage approaching or exceeding configured limits); high CPU utilization associated with response assembly.
  • Application: Kibana instance becoming unresponsive or restarting unexpectedly without infrastructure-level cause (GitHub Advisory).

Mitigation and workarounds

Elastic has released patched versions Kibana 9.3.8 and 9.4.4, which bound and deduplicate the user-supplied document field list before response assembly. Organizations should upgrade to these versions as the primary remediation (Elastic Advisory). As an interim workaround, restrict access to the Kibana Playground for RAG feature to trusted users only, or disable the feature entirely if it is not in active use. Additionally, monitoring Kibana instance memory and CPU consumption for abnormal spikes can help detect exploitation attempts.

Community reactions

Elastic published a security advisory (ESA-2026-91) on August 13, 2026, disclosing the vulnerability and announcing patched releases (Elastic Advisory). Tenable added detection coverage for the issue shortly after disclosure (Tenable). No significant independent researcher commentary or broad social media discussion has been observed beyond standard vulnerability tracking and aggregation sites.

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72677HIGH7.3
  • Kibana logoKibana
  • kibana-8.19
NoYesAug 13, 2026
CVE-2026-72675HIGH7.1
  • Kibana logoKibana
  • kibana-8.19
NoYesAug 13, 2026
CVE-2026-72681MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72680MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72674MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management