{"id":"BIT-kibana-2026-72668","summary":"Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation","details":"Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.","aliases":["BIT-elk-2026-72668","CVE-2026-72668"],"modified":"2026-10-01T10:11:19.582061112Z","published":"2026-10-01T09:27:56.739Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:node.js:*:*"]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72668"}],"affected":[{"package":{"name":"kibana","ecosystem":"Bitnami","purl":"pkg:bitnami/kibana"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.4.0"},{"fixed":"9.4.7"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/kibana/BIT-kibana-2026-72668.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"}]}],"schema_version":"1.9.0"}