CVE-2026-72644

Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-01 20:17

Updated : 2026-09-02 14:22


NVD link : CVE-2026-72644

Mitre link : CVE-2026-72644

CVE.ORG link : CVE-2026-72644


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-248

Uncaught Exception