CVE-2026-49092: Elastic Kibana

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.

Affected products

  • Elastic Kibana: from 9.4.0, before 9.4.3 (fixed in 9.4.3)

Published 2026-07-21. Last modified 2026-08-06.