Junglewise Threat Intelligence

CVE-2026-94400: Elastic Kibana denial of service via resource consumption

CVE-2026-94400 · Severity: medium · CVSS 6.5 · Published 2026-09-26

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a data visualization and analytics platform, contains a resource consumption vulnerability that allows authenticated attackers to trigger a denial of service. By allocating excessive resources through normal API requests, attackers can exhaust system resources and make Kibana unavailable to legitimate users.

Technical details

An uncontrolled resource consumption flaw (CWE-400) in Kibana allows authenticated attackers to cause denial of service through excessive allocation. The vulnerability requires login credentials (PR:L) but no user interaction, and is accessible over the network. Exploitation results in availability impact with no confidentiality or integrity compromise.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.21, 9.0.0 to 9.4.6, 9.5.0 to 9.5.2

Timeline

  • 2026-09-25: disclosed: ESA-2026-181 published
  • 2026-09-26: patched: Fixed in Kibana 8.19.22, 9.4.7, 9.5.3

References

Related threats