Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-21 20:17
Updated : 2026-08-06 13:06
NVD link : CVE-2026-49092
Mitre link : CVE-2026-49092
CVE.ORG link : CVE-2026-49092
JSON object : View
Products Affected
elastic
- kibana
CWE
CWE-863
Incorrect Authorization
