CVE-2026-72628 is a vulnerability in Elastic Kibana
Published on September 1, 2026
Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service
Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.
Vulnerability Analysis
CVE-2026-72628 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is a Data Amplification Vulnerability?
The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.
CVE-2026-72628 has been classified to as a Data Amplification vulnerability or weakness.
Products Associated with CVE-2026-72628
Want to know whenever a new CVE is published for Elastic Kibana? stack.watch will email you.
Affected Versions
Elastic Kibana:- Version 8.19.0, <= 8.19.20 is affected.
- Version 9.0.0, <= 9.4.5 is affected.
- Version 9.5.0, <= 9.5.1 is affected.