CVE-2026-49092
Received Received - Intake

Kibana Unintended Proxy Confused Deputy Vulnerability

Vulnerability report for CVE-2026-49092, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Elastic

Description

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
elastic kibana *
elastic kibana From 9.4.0 (inc) to 9.4.2 (inc)
elastic kibana 9.4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Confused Deputy issue in Kibana where a lower-privileged user can cause unauthorized data exposure. It occurs when a user accesses functionality not properly constrained by access controls, allowing them to process data they are not authorized to see using another user's privileges.

Detection Guidance

To detect CVE-2026-49092, check if your Kibana instance is running version 9.4.0 to 9.4.2. Verify if Entity Analytics is enabled and if lower-privileged users can access unauthorized data. No specific commands are provided, but monitoring for unusual data access patterns by lower-privileged users may help.

Impact Analysis

An attacker with lower privileges could access sensitive data they should not be able to see, leading to unauthorized information exposure. This could result in data leaks, privacy violations, or compliance breaches depending on the exposed data.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, which may violate GDPR's data protection requirements or HIPAA's privacy rules. Organizations using Kibana must address this to maintain compliance with these regulations.

Mitigation Strategies

Update Kibana to the latest patched version immediately to address the confused deputy vulnerability. Review user privileges and access controls to ensure proper ACL enforcement. Monitor logs for unauthorized data access attempts or unusual privilege escalations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49092. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart