Executive brief
Kibana is a data visualization and management dashboard for the Elastic Stack. A vulnerability in the Fleet management component allows an authorized user to crash or disable management services by providing malformed configuration data. This can prevent administrators from managing security agents and servers, potentially disrupting monitoring and security operations.
Technical details
An improper input validation vulnerability (CWE-20) exists in Kibana within the Fleet management component. An authenticated attacker with privileges to manage Fleet policies can submit a specially crafted policy input that is not correctly validated by the server. Successful exploitation leads to a denial of service (CAPEC-153), rendering Fleet agent, server, and policy management functionality unavailable. The issue is resolved in Kibana versions 8.19.17, 9.3.6, and 9.4.3. No workarounds are available for affected versions.
Affected products
- Elastic Kibana 8.0.0 to 8.19.16, 9.0.0 to 9.3.5, 9.4.0 to 9.4.2
Timeline
- 2026-07-01: disclosed
- 2026-07-01: patched: Fixed in 8.19.17, 9.3.6, and 9.4.3