LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-7609: Kibana Arbitrary Code Execution

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-7609 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jul 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

CVE-2019-7609 is an arbitrary code execution vulnerability in Elastic Kibana, specifically in the Timelion visualizer. It is tracked as a code injection weakness (CWE-94). For IT and security teams, this matters because successful abuse can let an attacker run code in the context of the Kibana process, which often sits on internal networks with access to Elasticsearch data and related infrastructure. Confirm exact impact, affected builds, and fixes against the vendor advisory.

CISA notes the flaw in the Timelion visualizer and directs organizations to apply updates per vendor instructions. Ransomware use is not documented in the provided facts; treat any exploitation as a serious compromise of the Kibana host and connected systems until proven otherwise.

How it works

CWE-94 covers improper control of code generation or evaluation, often called code injection. In products like Kibana, visualizers and query interfaces sometimes accept expressions or scripts that the application interprets. When input is not sufficiently constrained, an attacker who can reach the vulnerable feature may supply crafted content that the Timelion component evaluates in an unintended way, leading to arbitrary code execution under the privileges of the Kibana process.

Public detail in the given facts is limited to the presence of an arbitrary code execution flaw in Timelion. Do not assume a particular payload format, authentication requirement, or network exposure model; those specifics must be confirmed against the vendor advisory and your own deployment (for example whether Timelion is enabled and who can reach the Kibana UI or API). In general for this class, exploitation tends to require the ability to submit input that reaches the vulnerable interpreter, after which the attacker gains a foothold for further actions such as reading local files, moving laterally, or abusing credentials available to the service account.

Am I affected? How to find it in your systems

Kibana is commonly deployed as the visualization and management UI in front of Elasticsearch, in ELK/Elastic Stack environments, on-premises, in VMs/containers, or via cloud marketplaces. It may be exposed only on internal networks or, less ideally, to broader user populations.

How to remediate

Patch first. Apply the updates Elastic provides for this issue, following the vendor advisory and CISA’s direction to apply updates per vendor instructions. Schedule maintenance windows for all Kibana instances (including non-production if they hold sensitive data or share credentials), verify the fixed version is running after upgrade, and re-enable only required features.

If you can't patch immediately

Use compensating controls to reduce exposure until the vendor update is applied.

These measures lower risk but do not replace the patch. Track time-to-remediate and escalate any instance that remains vulnerable.

If your data may have been exposed

Actively exploited arbitrary code execution flaws can lead to full compromise of the application host and access to data the service can reach, including indices visible through Kibana. If you suspect exploitation, isolate affected hosts, preserve logs and memory images per your IR plan, rotate credentials and tokens available to the Kibana process, and review Elasticsearch access for unauthorized queries or exports. Ransomware use is not documented for this CVE in the given facts; still investigate for persistence and lateral movement. As a routine check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials appear in prior public breaches, then force resets and MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedElastic · Kibana
WeaknessCWE-94
Added to CISA KEVJan 10, 2022
Federal patch deadlineJul 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities