Denial of Service Vulnerability in Kibana by Elastic
CVE-2026-72674
6.5MEDIUM
What is CVE-2026-72674?
A vulnerability in Kibana's handling of user-supplied document fields for the RAG feature allows for excessive resource allocation. This weakness does not enforce limits on input size nor de-duplication, potentially leading to processing and memory strains that can exhaust the Kibana instance’s resources. An attacker could exploit this design flaw by submitting a specially crafted request, which would result in a response significantly larger than intended, causing service interruptions.
Affected Version(s)
Kibana 9.3.0 <= 9.3.7
Kibana 9.4.0 <= 9.4.3