Executive brief
Elastic Kibana, a popular data visualization and management platform, contains a vulnerability where sensitive information like session cookies and request headers may be recorded in plain text within application logs. This occurs only when the optional Application Performance Monitoring (APM) feature is enabled. If an unauthorized person or a system administrator gains access to these logs, they could potentially steal credentials or other sensitive data to compromise user accounts.
Technical details
A sensitive information disclosure vulnerability (CWE-532) exists in Elastic Kibana when optional Application Performance Monitoring (APM) instrumentation is enabled. The vulnerability causes Kibana to record sensitive request header values, including cookies, into application logs. An attacker with high privileges and network access to the log files could extract these credentials to facilitate further attacks. The issue affects versions 8.x and 9.x up to 9.1.5 and is remediated in versions 8.18.9, 8.19.6, 9.0.8, and 9.1.6. Users unable to upgrade should disable APM instrumentation as a mitigation.
Affected products
- Elastic Kibana 8.0.0 to 8.18.8, 8.19.0 to 8.19.5, 9.0.0 to 9.0.7, 9.1.0 to 9.1.5
Timeline
- 2026-07-01: advisory
- 2026-07-01: patched