Skip to content
ElasticCVE-2026-72668

Elastic Kibana: privilege escalation

High7.3CVE-2026-72668 · Published Sep 26, 2026

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.

Elastic advisory

Affected versions

PackageAffectedFixed in
Kibana
Product
>= 9.4.0, <= 9.4.6No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-441

More Elastic advisories

All Elastic
Advisory
Elasticsearch: resource exhaustion
Medium6.5Sep 26
Elasticsearch: resource exhaustion
Medium6.5Sep 26
Elasticsearch: resource exhaustion
Medium6.5Sep 26
Elasticsearch: resource exhaustion
Medium6.5Sep 26
Elastic Kibana: resource exhaustion
Medium6.5Sep 26
Elasticsearch: resource exhaustion
Medium4.9Sep 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.