MEDIUMVulnerability

CVE-2026-72676

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restricting it to safe characters. That identifier is later placed into a server-side script that Fleet Server builds as part of routine agent policy processing, so script syntax embedded in the identifier became part of the script that was executed rather than being treated as data.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00357
cve_id
CVE-2026-72676
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-13T20:17:28.257
last_modified
2026-08-28T15:32:26.217
epss_percentile
0.28642

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72676 — Ninja Signal Threat Intelligence | Ninja Signal