Description
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.
Published: 2026-08-13
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncaught exception (CWE-248) can occur when a Kibana case comment contains malformed link syntax. The exception is not handled, preventing the case from being displayed for any user that opens it. Consequently, the case becomes permanently inaccessible until the offending comment is removed. This denial of service can affect any use of the impacted Kibana instance.

Affected Systems

Elastic Kibana is affected. No specific version information is provided in the advisory, so all current releases may be vulnerable until a fix is widely deployed.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the attack requires an authenticated user with comment privileges who can create a malformed link. There is no EPSS score or KEV designation, suggesting the vulnerability is not currently widely exploited in the wild. The denial of service impact is confined to the affected case, but the lack of a graceful error path raises concern for reliability.

Generated by OpenCVE AI on August 13, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Elastic Kibana update once it is released.
  • Delete or edit any case comments that contain malformed link syntax to restore the case visibility.
  • Limit the ability to add comments to trusted users and enforce stricter input validation to prevent malformed link construction.

Generated by OpenCVE AI on August 13, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.
Title Uncaught Exception in Kibana Cases Leading to Denial of Service
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:26:34.030Z

Reserved: 2026-05-27T11:31:33.583Z

Link: CVE-2026-49096

cve-icon Vulnrichment

Updated: 2026-08-13T20:26:30.008Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:22.600

Modified: 2026-08-13T21:18:07.480

Link: CVE-2026-49096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:00:06Z

Weaknesses