Junglewise Threat Intelligence

CVE-2026-49087: Elastic Kibana denial of service in Timeline feature

CVE-2026-49087 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and exploration tool used to analyze large volumes of data. A vulnerability in the Timeline feature allows an authorized user to crash the application or make it unresponsive by sending a specially crafted data deletion request. This could lead to a service outage, preventing teams from accessing critical dashboards and monitoring tools.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in Kibana's Timeline feature due to improper throttling of bulk deletion requests. An authenticated attacker with access to the Timeline component can transmit a specially crafted request that leads to excessive memory or CPU allocation (CAPEC-130). This resource exhaustion can render the Kibana instance unavailable to other users. The vulnerability affects versions 8.x up to 8.19.14 and 9.x up to 9.3.3. Patches are available in versions 8.19.15 and 9.3.4.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.14, 9.0.0 to 9.3.3

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory
  • 2026-07-01: patched: Fixed in 8.19.15 and 9.3.4

References

Related threats