Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana server process to terminate and resulting in a denial of service for all users of the affected Kibana instance.
Affected Versions:
- 8.x: All versions from 8.0.0 up to and including 8.19.18
- 9.x:
- All versions from 9.3.0 up to and including 9.3.7
- All versions from 9.4.0 up to and including 9.4.3
Users on the 9.5.x release line are not affected. The fix was incorporated into Kibana 9.5.0 before that version was publicly released.
Affected Configurations:
- All Kibana deployments that allow authenticated user access are affected.
Solutions and Mitigations:
The issue is resolved in versions 8.19.19, 9.3.8, and 9.4.4.
For Users that Cannot Upgrade:
- There are no workarounds for this vulnerability.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-63139
Problem Type: CWE-400 - Uncontrolled Resource Consumption
Impact: CAPEC-130 - Excessive Allocation