« Volver al listado

CVE-2026-78586

Estado: AnalizadaMedia (6.5)—

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-78586",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-78586",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-02T15:45:37.476564Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@elastic.co",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@elastic.co",
      "affectedData": [
        {
          "vendor": "Elastic",
          "product": "Kibana",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.19.15"
            },
            {
              "status": "affected",
              "version": "9.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.3.4"
            },
            {
              "status": "affected",
              "version": "9.4.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.4.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-02T15:17:40.063",
  "references": [
    {
      "url": "https://discuss.elastic.co/t/kibana-8-19-16-9-3-5-9-4-2-security-update-esa-2026-163/390116",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@elastic.co"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@elastic.co",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users."
    }
  ],
  "lastModified": "2026-09-03T13:43:50.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43EDC5B3-131D-489E-8447-05C5C599E6A7",
              "versionEndExcluding": "8.19.16",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9B40710-912A-4157-9F25-89CE26C098A9",
              "versionEndExcluding": "9.3.5",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81FF6553-FE7A-475D-9D50-5D0FC66FE375",
              "versionEndExcluding": "9.4.2",
              "versionStartIncluding": "9.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@elastic.co"
}