Uncaught Exception in Kibana - CVE-2026-72660

 

Uncaught Exception in Kibana - CVE-2026-72660

Published: August 13, 2026


Vulnerability identifier: #VU142356
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72660
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an uncaught exception in the Kibana Security Solution feature set when processing specially crafted data that Kibana subsequently reads. A remote user can supply specially crafted data to cause a denial of service.

Exploitation requires an authenticated Kibana account with read access and the ability to write documents to at least one Elasticsearch index that Kibana subsequently reads.


Affected software

Kibana

How to mitigate CVE-2026-72660

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.3.8, 9.4.5

External References

Related Security Bulletins