{"id":"CVE-2026-72668","published":"2026-09-26T21:16:55.540","lastModified":"2026-09-29T04:17:57.373","description":"Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cwes":["CWE-441"],"vendors":[],"products":[],"references":[{"url":"https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}