CVE-2026-72668
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.
| CWE | CWE-441 |
| Vendor | elastic |
| Product | kibana |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for elastic kibana
Be the first to know when new high vulnerabilities affecting elastic kibana are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Elastic / Kibana
9.4.0 โค 9.4.6