{"id":"CVE-2026-72644","summary":"Uncaught Exception in Kibana Leading to Denial of Service","details":"Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.","modified":"2026-09-04T08:06:27.863808Z","published":"2026-09-01T19:20:19.542Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-248"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72644.json","unresolved_ranges":[{"extracted_events":[{"introduced":"9.1.7"},{"last_affected":"9.4.4"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-9-4-5-9-5-1-security-update-esa-2026-115/390088"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72644.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72644"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"49e091e266fdfecd2b3a96f9d390719838fb742d"},{"fixed":"adc1f04ffdd393d1977990338d5512c5eaf1ce94"},{"introduced":"8d4246a64bc255212407b1b313fe402391299c88"},{"last_affected":"8d4246a64bc255212407b1b313fe402391299c88"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.1.7"},{"fixed":"9.4.5"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.5.0","v9.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72644.json","vanir_signatures_modified":"2026-09-04T08:06:27Z","vanir_signatures":[{"source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighterTests.java"},"deprecated":false,"digest":{"line_hashes":["283190670438501987514727838726815920477","139872482520600089094968553951135983484","244928736363048457427079246025589015191"],"threshold":0.9},"id":"CVE-2026-72644-15fc2a3d","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"35973537492193988444530376691395407843","length":2369},"id":"CVE-2026-72644-3749bff4","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java","function":"setupParser"}},{"deprecated":false,"digest":{"line_hashes":["114508176030696626539066047296433779214","43384607500169746049581282043376952148","283563727296098110195444588655154165811","277031765205288332698033581440269116720","187407052376657667672985622362187421922","90126549817761157374395826113896432271","62431126033836515299954878706677890458","276372619117036678140958072933552714348","34204804071724460000309539643270206424","178874689487166837173458238589286447776"],"threshold":0.9},"id":"CVE-2026-72644-56785d56","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java"}},{"target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java","function":"highlight"},"deprecated":false,"digest":{"function_hash":"74600334261879604741521313242640339568","length":4662},"id":"CVE-2026-72644-687797ed","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94"},{"deprecated":false,"digest":{"length":176,"function_hash":"10160088286724545746756661846724288313"},"id":"CVE-2026-72644-6e669937","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"function":"getFieldType","file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java"}},{"id":"CVE-2026-72644-9734acfc","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/rest/action/search/SearchCapabilities.java"},"deprecated":false,"digest":{"line_hashes":["130192812032915568189929366428112074279","338587668112843751875004607897056457244","311636223832287298418351940618914661904","14559433973571236327103093772803942734","81766092491860980139880041074416541030","83778004218823664808743686188872036723","217672029278899031516016760140755058444"],"threshold":0.9}},{"id":"CVE-2026-72644-bd63b83e","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java"},"deprecated":false,"digest":{"line_hashes":["243868588130949656791143692081236563864","311505216586199373294314499230294889565","23300629379259170631342652985157100415","99779525804820300359777388439313924719","124392759507223488964887386448798184793","57056074566821104672192600168236166604","183428232184500482658775793061523078930"],"threshold":0.9}},{"source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java"},"deprecated":false,"digest":{"line_hashes":["122639132757664986803138175691671001655","335892283999867396276535502941166644649","252845685254806679929754126735709659653","70459544080609156892578956654685198979","288350301639674802567568120843372854348","128879439556083118790804565740578695567","183568503689704087885138164738553210791","315988264130765396628199666193426980549","110105306531665817097053229432225710351","108886619290626151118397149603734671098","68900764452827513161409585113073530589","109699481272201296627752008736891181922","89552474233322494405147063649180198152","243794874480578150177830085733756836217","128936352400535787295390066296206280301","168193967744077208144892951303807415035","32485489507345202777470620624306770167","82468793747458534960176489784612968344","95431536162858288727547312167888083055","79895802567313409968279279144916310561","109983373614664327492018760324106301607","254164139643632659290414288579740637195","218911482828271878345863242741149783938","290149128642774742559654272690374710990","129649976829885946269329561068451864187","271521553609249011929656203339955131993","116967678018103273313850160203491775016","34507466461561024444180968955125864688","149539466270008484339757108260134471872","241540141246676079432554907112288153733","247281622777097759942516432384261889326","8682106367820934505412234917026602498","258599880353756871245323998211345504441","140682565192181975671989624265695960587","100268892565605616091333444189761449681","214950598829781998119271592022997186976","200550104524719405385075838124186899375","313720121068230248463194804287647092807","188167255630204728049901172366742944889","197051329735330186721065881872811534640","246392715163119707808625433035684232434","127945619089996738346525337879859203179","136702270964155933380398036066653195170"],"threshold":0.9},"id":"CVE-2026-72644-ca3692e7","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"186492591955110081095185334864085897708","length":674},"id":"CVE-2026-72644-dc0a4f96","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java","function":"build"}},{"source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java","function":"testBuildSearchContextHighlight"},"deprecated":false,"digest":{"function_hash":"50460798663850937323875144151113267593","length":3586},"id":"CVE-2026-72644-e5c86fee","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java"},"deprecated":false,"digest":{"line_hashes":["250502453778712768962053518703255093608","293745187741608286289486472330502044902","92285933861987769382932879499624280339","48848052402887098574079705828368727963","180954780310110417851376237840132855867","265701660666103015958674140349152633739","219483656979539974598819100907886798376"],"threshold":0.9},"id":"CVE-2026-72644-f6f0ec86"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"6c427d979e2b3a65eea87f31ba4b65dc579ee2f0"},{"fixed":"bc80ff828630b51dd591207f43a54ea5ebf53270"},{"introduced":"240f7d17d21408117f4295bcf74d48092ab0d078"},{"last_affected":"240f7d17d21408117f4295bcf74d48092ab0d078"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.1.7"},{"fixed":"9.4.5"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.5.0","v9.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72644.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}