Kibana 9.4.5 Security Update (ESA-2026-97)

Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.

Affected Versions:

  • All versions from 9.1.0 up to and including 9.4.4

Affected Configurations:
All configurations are affected.

Solutions and Mitigations:

The issue is resolved in versions 9.4.5.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.8 ) - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVE ID: CVE-2026-72666
Problem Type: CWE-639 - Authorization Bypass Through User-Controlled Key
Impact: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs