CVE-2025-68389
Kibana vulnerability analysis and mitigation

Overview

CVE-2025-68389 is a denial-of-service vulnerability in Elastic Kibana caused by allocation of resources without limits or throttling (CWE-770). A low-privileged authenticated user can send a crafted HTTP request to trigger excessive allocation of computing resources, crashing the Kibana process. The vulnerability affects Kibana versions 7.0.0–7.17.29, 8.0.0–8.19.8, 9.0.0–9.1.8, and 9.2.0–9.2.2. It was disclosed on December 18, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Elastic Advisory, Red Hat Bugzilla).

Technical details

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling), where Kibana fails to impose adequate constraints on resource consumption triggered by certain HTTP requests. An authenticated attacker with low privileges can craft a specific HTTP request that causes the Kibana server process to allocate excessive computing resources, consistent with CAPEC-130 (Excessive Allocation). No authentication bypass is required — only a valid low-privileged account is needed to exploit this flaw over the network with low attack complexity and no user interaction (Red Hat Bugzilla, Elastic Advisory).

Impact

Successful exploitation results in a denial-of-service condition, crashing or rendering the Kibana process unresponsive. This disrupts access to Kibana's monitoring, logging, and visualization capabilities for all legitimate users. There is no confidentiality or integrity impact — the vulnerability is limited to availability (CVSS A:H). In environments where Kibana is central to security operations or observability pipelines, an outage could impair incident detection and response capabilities (Elastic Advisory, Red Hat Bugzilla).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.20%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Obtain low-privileged credentials: Acquire any valid Kibana user account — no elevated privileges are required.
  2. Identify target: Locate an internet-facing or network-accessible Kibana instance running a vulnerable version (7.0.0–7.17.29, 8.0.0–8.19.8, 9.0.0–9.1.8, or 9.2.0–9.2.2).
  3. Craft malicious HTTP request: Construct a specially crafted HTTP request designed to trigger unbounded resource allocation within the Kibana process. The specific endpoint and payload structure have not been publicly disclosed.
  4. Send the request: Authenticate to Kibana and submit the crafted request. The Kibana process begins allocating excessive computing resources.
  5. Achieve DoS: The Kibana process becomes unresponsive or crashes, denying service to all users until the process is restarted (Red Hat Bugzilla, Elastic Advisory).

Indicators of compromise

  • Logs: Kibana server logs showing sudden spikes in resource usage or process crashes; repeated HTTP requests from a single low-privileged user account to unusual or resource-intensive endpoints.
  • Process: Kibana process consuming abnormally high CPU or memory before crashing; unexpected Kibana process restarts or watchdog-triggered restarts.
  • Network: Unusual volume of HTTP requests from a single authenticated source IP targeting the Kibana service port (default 5601).
  • System: Operating system-level OOM (out-of-memory) killer events associated with the Kibana process; system logs indicating process termination due to resource exhaustion.

Mitigation and workarounds

Elastic has released patched versions addressing this vulnerability: Kibana 8.19.9, 9.1.9, and 9.2.3 (Elastic Advisory). Note that Kibana 7.x versions up to 7.17.29 are listed as affected; users on the 7.x branch should upgrade to a supported 8.x or 9.x release. As interim mitigations, administrators should restrict Kibana access to trusted users only, implement network-level rate limiting on the Kibana port, apply least-privilege principles to user accounts, and monitor for unusual resource consumption patterns.

Community reactions

The vulnerability was tracked by Red Hat's Product Security team via Bugzilla and assigned medium priority and severity (Red Hat Bugzilla). INCIBE-CERT (Spain's national cybersecurity agency) published an early warning advisory for the vulnerability. No significant public researcher commentary, social media discussion, or major media coverage has been identified beyond standard vulnerability database aggregation.

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63261MEDIUM6.5
  • Kibana logoKibana
  • kibana
NoYesJul 21, 2026
CVE-2026-63260MEDIUM6.5
  • Kibana logoKibana
  • kibana-8.19
NoYesJul 21, 2026
CVE-2026-63262MEDIUM4.3
  • Kibana logoKibana
  • kibana
NoYesJul 22, 2026
CVE-2026-63259MEDIUM4.3
  • Kibana logoKibana
  • kibana-9.4
NoYesJul 21, 2026
CVE-2026-63145MEDIUM4.3
  • Kibana logoKibana
  • kibana
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management