2026-09-26 20:42CVE-2026-72668elastic
PUBLISHED5.2CWE-441

Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.

Problem type

Affected products

Elastic

Kibana

<= 9.4.6 - AFFECTED

References

GitHub Security Advisories

GHSA-r4ff-jqf2-8p5g

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead...

https://github.com/advisories/GHSA-r4ff-jqf2-8p5g

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-72668
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-72668",
    "assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
    "assignerShortName": "elastic",
    "dateUpdated": "2026-09-26T20:42:09.858Z",
    "dateReserved": "2026-08-10T11:17:49.704Z",
    "datePublished": "2026-09-26T20:42:09.858Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
        "shortName": "elastic",
        "dateUpdated": "2026-09-26T20:42:09.858Z"
      },
      "title": "Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation",
      "descriptions": [
        {
          "lang": "en",
          "value": "Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Elastic",
          "product": "Kibana",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "9.4.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "9.4.6"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')",
              "cweId": "CWE-441",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-180",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 7.3,
            "baseSeverity": "HIGH"
          }
        }
      ]
    }
  }
}