Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Affected Versions:
- 9.x: All versions from 9.4.0 up to and including 9.4.2
- (8.x not affected)
Affected Configurations:
- Affects deployments that have enabled Entity Analytics. Exploitation requires an authenticated account with access to the affected functionality.
Solutions and Mitigations:
The issue is resolved in version 9.4.3.
For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
Severity: CVSSv3.1: Medium ( 4.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVE ID: CVE-2026-49092
Problem Type: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
Impact: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs