Description
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A confused‑deputy flaw in Kibana allows a lower‑privileged user to invoke functionality that operates with another user's privileges. This programming error means that data from sources the user is not authorized to access can be processed and returned, resulting in unauthorized disclosure of protected information.

Affected Systems

Elastic Kibana is affected. The CVE data does not provide specific affected release versions.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while an EPSS score of less than 1 % shows a very low probability of exploitation. The vulnerability is not listed in CISA KEV and no public exploits are documented. The attack requires an authenticated user with basic access to the Kibana interface or API who can trigger the unprotected call that forwards another user's identity. Because it is a privilege‑confusion issue rather than a remote code execution vector, practical risk is limited but still relevant for environments with sensitive data.

Generated by OpenCVE AI on July 30, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Kibana security patch released by Elastic
  • Ensure that access control lists for data sources are properly configured so that only authorized roles can read data, closing the privilege‑confusion path
  • Enable audit logging for data access requests and regularly review logs for anomalous activity that may indicate abuse of the exposed functionality

Generated by OpenCVE AI on July 30, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 21 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Title Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T18:26:06.728Z

Reserved: 2026-05-27T11:31:33.582Z

Link: CVE-2026-49092

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:51.810Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T20:17:01.610

Modified: 2026-08-06T13:06:04.560

Link: CVE-2026-49092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:45:04Z

Weaknesses