Cyber Resilience

CVE-2026-72746

Published
11 August 2026
Modified
12 August 2026
CVSS Score N/A
EPSS Score 0.0043 36th percentile
Risk Priority 0 floored blend · peak EPSS

Summary

CVE-2026-72746 is a uncategorised-severity an unspecified weakness vulnerability. Its CVSS base score is N/A.

Operationally, ranked at the 36th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-3 (Device Identification and Authentication) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.

CWE(s)
None listed

Related Threats

CVEs Like This One

CVE-2026-12255Shared CWE-287
CVE-2026-26128Shared CWE-287
CVE-2020-17523Shared CWE-287
CVE-2025-2230Shared CWE-287
CVE-2023-32524Shared CWE-287
CVE-2022-23178Shared CWE-287
CVE-2026-45289Shared CWE-287
CVE-2025-49012Shared CWE-287
CVE-2023-4373Shared CWE-287
CVE-2026-24241Shared CWE-287

Affected Assets

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

Mandates unique identification and authentication of organizational users before access, directly stopping improper authentication.

Requires unique identification and authentication of devices before establishing connections, preventing unauthenticated device claims.

Mandates unique identification and authentication of non-organizational users, directly addressing the weakness for external actors.

Manages authenticators with verification and secure distribution, reducing opportunities for improper authentication.

Enforces access only after approved authorizations, which presupposes correct authentication has occurred.

References