Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 26 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.
Title Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation
Weaknesses CWE-441
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-26T20:42:09.858Z

Reserved: 2026-08-10T11:17:49.704Z

Link: CVE-2026-72668

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-26T21:16:55.540

Modified: 2026-09-26T21:16:55.540

Link: CVE-2026-72668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses