Junglewise Threat Intelligence

CVE-2026-33459: Elastic Kibana denial of service in automatic import feature

CVE-2026-33459 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

A vulnerability in Kibana, a popular data visualization and management platform, could allow an authorized user to crash the service. By sending specially crafted requests to the automatic import feature, an attacker can exhaust system resources, making the platform unavailable to all other users. This disruption can halt data analysis operations and monitoring dashboards across the organization.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in Kibana's automatic import plugin, which is enabled by default in version 8.15 and later. The flaw allows an authenticated user with Fleet and Integrations privileges to trigger excessive memory or CPU allocation (CAPEC-130) by submitting requests with excessively large input values. When multiple such requests are processed concurrently, the backend services become unstable, leading to a denial-of-service (DoS) condition. The issue is resolved in Kibana versions 8.19.14, 9.2.8, and 9.3.3.

Affected products

  • Elastic Kibana 8.15.0 to 8.19.13, 9.0.0 to 9.2.7, 9.3.0 to 9.3.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats