PT-2026-99425 · Elastic · Kibana+1

CVE-2026-72668

·

Published

2026-09-26

·

Updated

2026-09-29

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description A Confused Deputy issue in Kibana Agent Builder allows a non-administrative user with permissions to edit a shared agent to trigger privileged operations. These operations are executed using the identity of a higher-privileged user who interacts with the modified agent. If the attacker also has the ability to author workflows, this can lead to full administrative control over Kibana and the associated Elasticsearch cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72668

Affected Products

Elasticsearch
Kibana