# Kibana 9.4.1 xpack disabled not working anymore

**URL:** <https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347>\
**Category:** Kibana\
**Created:** [May 14, 2026, 11:18pm UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347 "2026-05-14T23:18:46Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [May 14, 2026, 11:18pm UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/1 "2026-05-14T23:18:46Z")

</div>

I can't access Kibana with xpack security disabled since upgrading my test setup to 9.4.1

I'm proxying Kibana with nginx

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 15, 2026, 8:21am UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/2 "2026-05-15T08:21:33Z")

</div>

Can you provide more details from kibana.log?

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [May 17, 2026, 9:38pm UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/3 "2026-05-17T21:38:33Z")

</div>

Sure, same as here

Setting the password for elastic and kibana\_system and enabling xpack seems to at least allow me to access the kibana instance, however for dev work it would be great not to have to worry about xpack.

> <https://github.com/elastic/kibana/issues/268959>
>
> \*\*Kibana version:\*\* 9.4.1
> 
> \*\*Elasticsearch version:\*\* 9.4.1
> 
> Tested with 9.4.0 a…s well. 9.3.4 works.
> 
> \*\*Original install method (e.g. download page, yum, from source, etc.):\*\* Docker
> 
> \*\*Describe the bug:\*\*
> 
> I run a test setup without security, i.e., \`xpack.security.enabled=false\` for ES. As soon as I upgrade the stack to 9.4.0, Kibana tries to call an ES HTTP API endpoint that does not exist. Previous upgrades to 9.3.4 were all successful.
> 
> \`\`\`
> Failed to activate user profile: {"error":"no handler found for uri \[/\_security/profile/\_activate\] and method \[POST\]"}.
> \`\`\`
> 
> \`\`\`yaml
> services:
> search:
> image: docker.elastic.co/elasticsearch/elasticsearch:9.4.1
> environment:
> # Single-node setup with bootstrap checks that are disabled in single-node.
> - discovery.type=single-node
> - ES\_JAVA\_OPTS=-Des.enforce.bootstrap.checks=true
> 
> - node.name=search01
> - cluster.name=testing-cluster
> # No security.
> - xpack.security.enabled=false
> 
> kibana:
> image: docker.elastic.co/kibana/kibana:9.4.1
> ports:
> - 5601:5601
> environment:
> ELASTICSEARCH\_HOSTS: http://search:9200
> \`\`\`

````auto
{
  "http": {
    "response": {
      "status_code": 500
    },
    "request": {
      "method": "get",
      "path": "/app/{id}/{any*}"
    }
  },
  "error": {
    "message": "{\"error\":\"no handler found for uri [/_security/profile/u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0?data=kibana.userSettings] and method [GET]\"}"
  },
  "service": {
    "version": "9.4.1",
    "type": "kibana",
    "state": "available",
    "node": {
      "roles": [
        "background_tasks",
        "ui"
      ]
    },
    "id": "ohvI5dqKTj-lfM4SXTl9jw"
  },
  "ecs": {
    "version": "9.3.0"
  },
  "@timestamp": "2026-05-18T14:54:32.044+10:00",
  "message": "500 Server Error",
  "log": {
    "level": "ERROR",
    "logger": "http"
  },
  "process": {
    "pid": 23545,
    "uptime": 485.247554952
  },
  "trace": {
    "id": "ce1b5f71c58f59f151cc626e86182dba"
  },
  "transaction": {
    "id": "5ff7736e2b52d840"
  }
}
```

````

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 26, 2026, 2:10pm UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/4 "2026-05-26T14:10:16Z")

</div>

I have pinged the Kibana team internally.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 27, 2026, 10:41am UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/5 "2026-05-27T10:41:08Z")

</div>

Hey @VamPikmin ,

Can you share a bit more details about your proxy setup? Does the proxy attach "Authorization" HTTP header or something along these lines?

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [May 27, 2026, 10:42am UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/6 "2026-05-27T10:42:13Z")

</div>

> [@VamPikmin](#):
>
> ```auto
> "http": {
> "response": {
> "status_code": 500
> },
> "request": {
> "method": "get",
> "path": "/app/{id}/{any*}"
> }
> },
> 
> ```

That same path `/app/{id}/{any*}"`, came up in a different [thread](https://discuss.elastic.co/t/elasticsearch-kibana-9-4-0-basic-authentication-returns-401-unauthorized/386318) last week, where while troubleshooting that issue we possibly hit this one too.

Note OP in that other thread deemed a `:` character in his password as the core issue, and there were other unrelated complications, but he was also using a proxy (apache in his case).

---

<div class="post-metadata">

**Author:** ![Dheeraj\_Gupta](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Post date:** [May 27, 2026, 11:33am UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/7 "2026-05-27T11:33:39Z")

</div>

This was the problem in our case. After configuring Nginx to strip the Authorization header (we use Nginx basic auth to secure kibana endpoint at reverse proxy level), 9.4 also works correctly.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 27, 2026, 11:47am UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/8 "2026-05-27T11:47:50Z")

</div>

Thanks for confirming. We'll keep discussing the issue, workarounds, and the possibility of restoring the previous behavior in [https://github.com/elastic/kibana/issues/268959](https://github.com/elastic/kibana/issues/268959). I'll mark the last message in this thread as a solution for now.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [May 28, 2026, 10:50pm UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347/9 "2026-05-28T22:50:00Z")

</div>

Apologies,

Yes I'm using nginx and stripping the header resolves the issue

```auto

proxy_set_header Authorization "";

```

Thanks
