# Kibana 9.4.7, 9.5.0 Security Update (ESA-2026-85)

**URL:** https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678
**Category:** Security Announcements
**Created:** [September 25, 2026, 8:31am UTC](https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678 "2026-09-25T08:31:59Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![kruskall](https://avatars.discourse-cdn.com/v4/letter/k/ac91a4/32.png) [@kruskall](https://discuss.elastic.co/u/kruskall)
#### Post date: [September 25, 2026, 8:31am UTC](https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678/1 "2026-09-25T08:31:59Z")

</div>

**Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation**

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.

**Affected Versions:**

- 9.x: All versions from 9.4.0 up to and including 9.4.6

Users on the 8.x release line and on 9.3.x and earlier are not affected. The combination of Agent Builder and Workflows functionality that contains this vulnerability was introduced in Kibana 9.4.0.

**Affected Configurations:**

- Kibana deployments running an affected version with the Agent Builder and Workflows features enabled; both are enabled by default
- A generative AI connector is configured for Agent Builder
- Exploitation requires a non-administrative authenticated user holding the Agent Builder privilege to manage agents together with the Workflows privilege to create workflows, and no Elasticsearch cluster privileges
- Exploitation also requires that a higher-privileged user subsequently interacts with the affected agent

**Solutions and Mitigations:**

The issue is resolved in Kibana version 9.4.7, 9.5.0.

**For Users that Cannot Upgrade:**

- Disable the Workflows feature in Kibana. This removes all Workflows functionality.
- Review the workflows attached to existing agents, including the default assistant, and remove any that were not configured by an administrator.

**Indicators of Compromise (IOC)**

Kibana audit log entries recording changes to Agent Builder agent configurations by users who are not administrators, and the creation or modification of Elasticsearch users, roles, or API keys coinciding with Agent Builder activity by a privileged user, may indicate exploitation of this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: High ( 7.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N  
**CVE ID:** CVE-2026-72668  
**Problem Type:** CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')  
**Impact:** CAPEC-180 - Exploiting Incorrectly Configured Access Control Security Levels
