Junglewise Threat Intelligence

CVE-2026-56151: Elastic Kibana denial of service in Fleet policy management

CVE-2026-56151 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and management dashboard for the Elastic Stack. A vulnerability in the Fleet management component allows an authorized user to crash or disable management services by providing malformed configuration data. This can prevent administrators from managing security agents and servers, potentially disrupting monitoring and security operations.

Technical details

An improper input validation vulnerability (CWE-20) exists in Kibana within the Fleet management component. An authenticated attacker with privileges to manage Fleet policies can submit a specially crafted policy input that is not correctly validated by the server. Successful exploitation leads to a denial of service (CAPEC-153), rendering Fleet agent, server, and policy management functionality unavailable. The issue is resolved in Kibana versions 8.19.17, 9.3.6, and 9.4.3. No workarounds are available for affected versions.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.16, 9.0.0 to 9.3.5, 9.4.0 to 9.4.2

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: patched: Fixed in 8.19.17, 9.3.6, and 9.4.3

References

Related threats