Unintended Proxy Vulnerability in Kibana by Elastic
CVE-2026-49092

4.3MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-49092?

An unintended proxy vulnerability exists in Kibana that allows lower-privileged users to exploit access control mechanisms. This results in unauthorized exposure of sensitive information as data from restricted sources can be processed under another user’s privileges. It poses significant risks if malicious actors leverage this flaw, compromising data integrity and confidentiality. Proper access control measures must be enforced to mitigate these risks.

Affected Version(s)

Kibana 9.4.0 <= 9.4.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.