CVE-2026-49092: Elastic Kibana
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Affected products
- Elastic Kibana: from 9.4.0, before 9.4.3 (fixed in 9.4.3)
Published 2026-07-21. Last modified 2026-08-06.