# Kibana 8.19.19, 9.3.8, 9.4.4 Security Update (ESA-2026-63)

**URL:** <https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-63/388560>\
**Category:** Security Announcements\
**Created:** [July 21, 2026, 8:32pm UTC](https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-63/388560 "2026-07-21T20:32:06Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [July 21, 2026, 8:32pm UTC](https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-63/388560/1 "2026-07-21T20:32:06Z")

</div>

**Uncontrolled Resource Consumption in Kibana Leading to Denial of Service**

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana server process to terminate and resulting in a denial of service for all users of the affected Kibana instance.

**Affected Versions:**

- 8.x: All versions from 8.0.0 up to and including 8.19.18
- 9.x:
  - All versions from 9.3.0 up to and including 9.3.7
  - All versions from 9.4.0 up to and including 9.4.3

Users on the 9.5.x release line are not affected. The fix was incorporated into Kibana 9.5.0 before that version was publicly released.

**Affected Configurations:**

- All Kibana deployments that allow authenticated user access are affected.

**Solutions and Mitigations:**

The issue is resolved in versions 8.19.19, 9.3.8, and 9.4.4.

**For Users that Cannot Upgrade:**

- There are no workarounds for this vulnerability.

**Indicators of Compromise (IOC)**

No specific indicators of compromise have been identified for this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**CVE ID:** CVE-2026-63139  
**Problem Type:** CWE-400 - Uncontrolled Resource Consumption  
**Impact:** CAPEC-130 - Excessive Allocation
