
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72674 is a Denial of Service vulnerability in Elastic Kibana caused by Allocation of Resources Without Limits or Throttling (CWE-770) in the Kibana Playground for RAG (Retrieval-Augmented Generation) feature. A user-supplied list of document fields is neither bounded in length nor de-duplicated before being used to assemble responses, allowing a single crafted request to trigger excessive memory and processing consumption. Affected versions are Kibana 9.3.0 through 9.3.7 and 9.4.0 through 9.4.3. It was published on August 13, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in Kibana's Playground for RAG feature. When a user submits a request to this feature, the list of document fields provided is passed directly into response assembly logic without any length cap or deduplication step, enabling an amplification effect where the resulting response can be orders of magnitude larger than the source data. Exploitation requires only a network-accessible Kibana instance and a low-privileged authenticated account with access to the Playground for RAG feature; no special configuration or chaining is needed. The attack pattern aligns with CAPEC-130 (Excessive Allocation) (GitHub Advisory, Elastic Advisory).
Successful exploitation causes the targeted Kibana instance to exhaust its memory and CPU resources, resulting in a crash or sustained unresponsiveness — a complete availability impact. There is no confidentiality or integrity impact, as the vulnerability does not expose data or allow modification of content. The scope is limited to the Kibana instance itself, but loss of Kibana availability can disrupt observability, security monitoring, and data analytics workflows that depend on it (GitHub Advisory, Elastic Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as not automatable, reflecting the requirement for authenticated access. The EPSS score is approximately 0.289%, placing it in the 22nd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
Elastic has released patched versions Kibana 9.3.8 and 9.4.4, which bound and deduplicate the user-supplied document field list before response assembly. Organizations should upgrade to these versions as the primary remediation (Elastic Advisory). As an interim workaround, restrict access to the Kibana Playground for RAG feature to trusted users only, or disable the feature entirely if it is not in active use. Additionally, monitoring Kibana instance memory and CPU consumption for abnormal spikes can help detect exploitation attempts.
Elastic published a security advisory (ESA-2026-91) on August 13, 2026, disclosing the vulnerability and announcing patched releases (Elastic Advisory). Tenable added detection coverage for the issue shortly after disclosure (Tenable). No significant independent researcher commentary or broad social media discussion has been observed beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."