CVE-2026-33459
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-33459 is an Uncontrolled Resource Consumption (CWE-400) vulnerability in Elastic Kibana that can lead to denial of service via excessive allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values; when sent concurrently, these requests destabilize backend services and render the deployment unavailable for all users. Affected versions include Kibana 8.15.0–8.19.13, 9.0.0–9.2.7, and 9.3.0–9.3.2. The vulnerability was published on April 8, 2026, with patches released for versions 8.19.14, 9.2.8, and 9.3.3. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), where Kibana's automatic import feature fails to enforce adequate limits on input size or request rate. An authenticated attacker can craft HTTP requests containing excessively large input values and submit them concurrently to the automatic import endpoint, triggering excessive memory or CPU allocation on backend services. No input validation or resource throttling is applied to reject or limit oversized payloads, allowing the attacker to exhaust available resources. The attack pattern aligns with CAPEC-130 (Excessive Allocation) and has secondary relevance to CAPEC-492 (Regular Expression Exponential Blowup) and CAPEC-147 (XML Ping of the Death) (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation results in a denial of service affecting the availability of the entire Kibana deployment for all users, not just the attacker. Backend services become unstable under concurrent oversized requests, causing service disruption and deployment unavailability. There is no impact on data confidentiality or integrity — the vulnerability is purely an availability concern. Organizations relying on Kibana for security monitoring, log analysis, or operational dashboards could experience significant operational disruption during an attack (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.039–0.053%, placing it in the 17th percentile for exploitation likelihood within 30 days. Exploitation requires authentication (low-privilege access) and the ability to reach the automatic import feature, which somewhat limits the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Elastic Advisory).

Exploitation steps

  1. Reconnaissance: Identify Kibana instances running affected versions (8.15.0–8.19.13, 9.0.0–9.2.7, or 9.3.0–9.3.2) exposed over the network, using version disclosure from the Kibana UI or API endpoints.
  2. Authentication: Obtain valid low-privilege credentials for the Kibana instance — any authenticated user with access to the automatic import feature is sufficient.
  3. Craft oversized requests: Construct HTTP requests targeting the automatic import feature endpoint with excessively large input values in the request body or parameters.
  4. Concurrent submission: Use a tool such as curl, ab (Apache Bench), or a custom script to send multiple such oversized requests simultaneously, maximizing resource consumption on the backend.
  5. Achieve denial of service: The concurrent oversized requests exhaust backend resources (memory/CPU), causing backend services to become unstable and the Kibana deployment to become unavailable for all users (GitHub Advisory).

Indicators of compromise

  • Network: Unusually high volume of concurrent HTTP POST requests to Kibana's automatic import API endpoint from a single or small set of source IPs; requests with abnormally large payload sizes.
  • Logs: Kibana server logs showing repeated large-payload requests to the automatic import endpoint; error messages indicating resource exhaustion, out-of-memory conditions, or service crashes in Kibana application logs.
  • Process: Kibana Node.js process exhibiting abnormally high CPU or memory utilization; frequent process restarts or crashes correlating with bursts of inbound requests.
  • Availability: Sudden and sustained unavailability of the Kibana UI or API for all users coinciding with the above network or log indicators (GitHub Advisory).

Mitigation and workarounds

Elastic has released patched versions addressing this vulnerability: 8.19.14, 9.2.8, and 9.3.3. Organizations should upgrade to one of these versions as the primary remediation. As interim workarounds, administrators should implement rate limiting and request size validation on the automatic import feature, restrict access to the automatic import feature to trusted users only, and monitor backend resource consumption for unusual spikes. Input validation to reject requests with excessively large values should also be considered if immediate patching is not feasible (Elastic Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72677HIGH7.3
  • Kibana logoKibana
  • kibana-8.19
NoYesAug 13, 2026
CVE-2026-72675HIGH7.1
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72681MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72680MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.4
NoYesAug 13, 2026
CVE-2026-72674MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management