Executive brief
A vulnerability in Kibana's Canvas feature allows an authenticated user to crash the server by sending a specially crafted request. This results in a denial of service, making the data visualization platform unavailable to all users. Organizations relying on Kibana for real-time monitoring and dashboards may experience operational blindness during an attack.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in Kibana's Canvas functionality due to excessive memory or CPU allocation (CAPEC-130). An authenticated user with low privileges can trigger this by sending a specially crafted network request to the Kibana server. This causes the server process to terminate, resulting in a complete denial of service for the instance. The issue is resolved in Kibana versions 8.19.19, 9.3.8, and 9.4.4. No workarounds are available other than upgrading.
Affected products
- Elastic Kibana 8.0.0 to 8.19.18, 9.3.0 to 9.3.7, 9.4.0 to 9.4.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched: Fixed in versions 8.19.19, 9.3.8, and 9.4.4