Junglewise Threat Intelligence

CVE-2026-49096: Elastic Kibana uncaught exception in Cases

CVE-2026-49096 · Severity: medium · CVSS 4.3 · Published 2026-08-13

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana Cases is a feature in the Elastic Stack for managing incident response and case work. An authenticated user with permission to comment on cases can inject malformed link syntax into a case comment, which causes an unhandled error when other users try to view that case. This renders the affected case inaccessible to all users until the malicious comment is manually removed, impacting incident response workflows and team productivity.

Technical details

The vulnerability is an uncaught exception (CWE-248) in Kibana's Cases feature that fails to validate or sanitize malformed link syntax in case comments. When a case comment containing crafted link syntax is later formatted for display, the application crashes with an unhandled error, preventing the case from being rendered. The attack requires authentication and the privilege to comment on cases (authenticated, network-reachable, no user interaction required beyond posting the comment). An authenticated attacker can achieve denial of service by rendering specific cases inaccessible to all users. The issue is patched in Kibana versions 8.19.20, 9.3.5, and 9.4.2.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.19, 9.0.0 to 9.3.4, 9.4.0 to 9.4.1

Timeline

  • 2026-08-13: disclosed: Vulnerability disclosed in ESA-2026-136
  • 2026-08-13: patched: Fixed in Kibana 8.19.20, 9.3.5, 9.4.2

References

Related threats