Description
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncaught exception in Kibana, caused by improper input validation, is triggered when an authenticated user with low privileges submits specially crafted data. The exception propagates on an execution path and terminates the entire Kibana process. As a result, the service becomes unavailable to all users until a restart is performed, and the condition can be repeated. The impact is a complete denial of service to the Kibana instance, affecting confidentiality and availability of the application’s functionality.

Affected Systems

Elastic Kibana is the only vendor/product listed as affected; no specific version information is provided in the CNA data. The vulnerability applies to any Kibana installation where the affected code paths are active.

Risk and Exploitability

The CVSS score of 6.5 classifies the risk as medium, but the lack of a containment mechanism means the denial of service can be repeatedly triggered. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower current exploitation probability but a non‑negligible threat if the patch is not applied. The likely attack vector requires an authenticated session with low‑privileged access, requiring the attacker to interact with Kibana’s API or UI to submit the malformed input.

Generated by OpenCVE AI on August 13, 2026 at 21:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update released by Elastic (ESA‑2026‑101).
  • Restart the Kibana service after the update to load the patched binaries.
  • Configure monitoring to alert on unexpected terminations or repeated restarts caused by uncaught exceptions.

Generated by OpenCVE AI on August 13, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.
Title Uncaught Exception in Kibana Leading to Denial of Service
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:30:59.966Z

Reserved: 2026-08-10T11:17:45.102Z

Link: CVE-2026-72660

cve-icon Vulnrichment

Updated: 2026-08-13T20:30:56.498Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:26.317

Modified: 2026-08-13T21:18:10.877

Link: CVE-2026-72660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses