云虫漏洞库

CVE-2026-72660 - Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the servic - 漏洞详情

漏洞编号:CVE-2026-72660

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-72660

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-248

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.

相关链接

相关漏洞

« 返回首页