Denial of Service Vulnerability in Kibana by Elastic
CVE-2026-72663
6.5MEDIUM
What is CVE-2026-72663?
An inefficient algorithmic complexity vulnerability in Kibana allows attackers to execute specially crafted deeply nested expressions. This can manipulate input data, leading to denial of service. When processed, these expressions create a disproportionate load on the system, consuming Kibana's request-processing thread indefinitely. As a result, Kibana becomes unresponsive to any additional requests until the service is manually restarted.
Affected Version(s)
Kibana 8.0.0 <= 8.19.19
Kibana 9.0.0 <= 9.4.4