ElasticCVE-2026-72668
Elastic Kibana: privilege escalation
High7.3CVE-2026-72668 · Published Sep 26, 2026
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Kibana Product | >= 9.4.0, <= 9.4.6 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-441
More Elastic advisories
All Elastic| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 26 | Elasticsearch: resource exhaustion | Medium6.5 | No fix yet |
| Sep 26 | Elasticsearch: resource exhaustion | Medium6.5 | No fix yet |
| Sep 26 | Elasticsearch: resource exhaustion | Medium6.5 | No fix yet |
| Sep 26 | Elasticsearch: resource exhaustion | Medium6.5 | No fix yet |
| Sep 26 | Elastic Kibana: resource exhaustion | Medium6.5 | No fix yet |
| Sep 26 | Elasticsearch: resource exhaustion | Medium4.9 | No fix yet |