CVE-2026-72746
Summary
CVE-2026-72746 is a uncategorised-severity an unspecified weakness vulnerability. Its CVSS base score is N/A.
Operationally, ranked at the 36th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-3 (Device Identification and Authentication) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-56136
Vulnerability Data
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Mandates unique identification and authentication of organizational users before access, directly stopping improper authentication.
Requires unique identification and authentication of devices before establishing connections, preventing unauthenticated device claims.
Mandates unique identification and authentication of non-organizational users, directly addressing the weakness for external actors.
Manages authenticators with verification and secure distribution, reducing opportunities for improper authentication.
Enforces access only after approved authorizations, which presupposes correct authentication has occurred.
References
- No references listed