SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72644

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana is vulnerable to a denial of service due to an uncaught exception that can be triggered by an authenticated user with low-privileged access through input data manipulation. This flaw allows the user to submit a crafted request that causes the Kibana process to crash, affecting all users and spaces until the service is restarted. Organizations using Kibana, particularly those with low-privileged user access, should prioritize addressing this vulnerability to maintain service availability.

CVE
CVE-2026-72644
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.

Related CVEs

Other vulnerabilities affecting the same vendor(s)