Executive brief
Kibana, a widely-used data visualization and exploration platform, contains a flaw that allows authenticated users to submit specially crafted requests that consume excessive system resources. An attacker with low-level user credentials could exploit this to make Kibana unavailable to all users, disrupting business operations and access to critical analytics and monitoring data.
Technical details
The vulnerability is a resource exhaustion flaw (CWE-770) in Kibana that lacks proper limits or throttling on resource allocation. An authenticated attacker with low-level permissions can craft and submit a malicious request that triggers excessive resource consumption (CPU, memory, or other system resources), leading to denial of service. The attack requires network access and valid authentication credentials, but no special user interaction is needed. The impact is service unavailability; no data exposure or integrity compromise occurs. Patches are available in Kibana 8.19.17, 9.3.0, and later versions.
Affected products
- Elastic Kibana 8.0.0 to 8.19.16, 9.0.0 to 9.2.8
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Patches available in Kibana 8.19.17 and 9.3.0 or later