Kibana 9.4.4 Security Update (ESA-2026-83)

Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.

Affected Versions:

  • All versions from 9.4.0 up to and including 9.4.3

Affected Configurations:

  • All configurations are affected.

Solutions and Mitigations:

The issue is resolved in version 9.4.4.

For Users that Cannot Upgrade:

  • There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE ID: CVE-2026-72681
Problem Type: CWE-862 - Missing Authorization