Junglewise Threat Intelligence

CVE-2026-63139: Elastic Kibana denial of service in Canvas functionality

CVE-2026-63139 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

A vulnerability in Kibana's Canvas feature allows an authenticated user to crash the server by sending a specially crafted request. This results in a denial of service, making the data visualization platform unavailable to all users. Organizations relying on Kibana for real-time monitoring and dashboards may experience operational blindness during an attack.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in Kibana's Canvas functionality due to excessive memory or CPU allocation (CAPEC-130). An authenticated user with low privileges can trigger this by sending a specially crafted network request to the Kibana server. This causes the server process to terminate, resulting in a complete denial of service for the instance. The issue is resolved in Kibana versions 8.19.19, 9.3.8, and 9.4.4. No workarounds are available other than upgrading.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.18, 9.3.0 to 9.3.7, 9.4.0 to 9.4.3

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched: Fixed in versions 8.19.19, 9.3.8, and 9.4.4

References

Related threats