Junglewise Threat Intelligence

CVE-2026-72644: Elastic Kibana uncaught exception in Observability AI Assistant

CVE-2026-72644 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is Elastic's visualization and analytics platform used to explore and visualize data from Elasticsearch. A flaw in the Observability AI Assistant feature allows authenticated users to crash the Kibana process through a malformed request, causing a denial of service that affects all users and spaces until the service is manually restarted. The vulnerability requires only low-privileged access and Enterprise licensing.

Technical details

The vulnerability is an uncaught exception (CWE-248) in the Observability AI Assistant component that can be triggered via input data manipulation (CAPEC-153). An authenticated user with access to the AI Assistant feature can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process. The attack requires network connectivity to Kibana, authentication credentials, and the feature to be enabled (requiring Enterprise or trial license with a configured generative AI connector). The impact is denial of service affecting all users on the instance. The vulnerability affects Kibana 9.x versions from 9.1.7 through 9.4.4 and 9.5.0; versions 8.x and earlier are unaffected. Patches are available in Kibana 9.4.5 and 9.5.1.

Affected products

  • Elastic Kibana 9.1.7 to 9.4.4, 9.5.0

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Patches released in Kibana 9.4.5 and 9.5.1

References

Related threats