云虫漏洞库

CVE-2026-49096 - Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened - 漏洞详情

漏洞编号:CVE-2026-49096

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-49096

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-248

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.

相关链接

相关漏洞

« 返回首页