Executive brief
Kibana, a data visualization and analytics platform, contains a resource consumption vulnerability that allows authenticated attackers to trigger a denial of service. By allocating excessive resources through normal API requests, attackers can exhaust system resources and make Kibana unavailable to legitimate users.
Technical details
An uncontrolled resource consumption flaw (CWE-400) in Kibana allows authenticated attackers to cause denial of service through excessive allocation. The vulnerability requires login credentials (PR:L) but no user interaction, and is accessible over the network. Exploitation results in availability impact with no confidentiality or integrity compromise.
Affected products
- Elastic Kibana 8.0.0 to 8.19.21, 9.0.0 to 9.4.6, 9.5.0 to 9.5.2
Timeline
- 2026-09-25: disclosed: ESA-2026-181 published
- 2026-09-26: patched: Fixed in Kibana 8.19.22, 9.4.7, 9.5.3