Uncaught Exception in Kibana - CVE-2026-72660
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an uncaught exception in the Kibana Security Solution feature set when processing specially crafted data that Kibana subsequently reads. A remote user can supply specially crafted data to cause a denial of service.
Exploitation requires an authenticated Kibana account with read access and the ability to write documents to at least one Elasticsearch index that Kibana subsequently reads.