CVE-2024-37279: Elastic Kibana

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

Affected products

  • Elastic Kibana: from 8.6.3, before 8.14.0 (fixed in 8.14.0)

Published 2024-06-13. Last modified 2026-06-17.