Executive brief
Kibana is a web-based analytics and visualization platform for Elasticsearch data. An authenticated user with maintenance window management privileges can submit a malicious request that causes Kibana to consume excessive memory or CPU resources, making it unresponsive and unavailable to all users until manually restarted. This impacts business visibility into critical operational metrics and logs.
Technical details
The vulnerability is a resource exhaustion flaw (CWE-770) in Kibana's maintenance window handling functionality. An authenticated user who is authorized to manage maintenance windows can craft a malformed payload that triggers uncontrolled resource allocation in the Kibana process. The attack requires authentication and the maintenance window management privilege, but no user interaction is needed from other users. Successful exploitation results in denial of service affecting all Kibana users, with no automatic recovery without manual intervention. The vulnerability is patched in versions 8.19.19, 9.3.8, and 9.4.4; no workarounds are available.
Affected products
- Elastic Kibana 8.12.0–8.19.18, 9.0.0–9.3.7, 9.4.0–9.4.3
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: Versions 8.19.19, 9.3.8, and 9.4.4 released