PT-2026-99425 · Elastic · Kibana+1
CVE-2026-72668
·
Published
2026-09-26
·
Updated
2026-09-29
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
A Confused Deputy issue in Kibana Agent Builder allows a non-administrative user with permissions to edit a shared agent to trigger privileged operations. These operations are executed using the identity of a higher-privileged user who interacts with the modified agent. If the attacker also has the ability to author workflows, this can lead to full administrative control over Kibana and the associated Elasticsearch cluster.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch
Kibana