Unintended Proxy Vulnerability in Kibana by Elastic
CVE-2026-49092
4.3MEDIUM
What is CVE-2026-49092?
An unintended proxy vulnerability exists in Kibana that allows lower-privileged users to exploit access control mechanisms. This results in unauthorized exposure of sensitive information as data from restricted sources can be processed under another user’s privileges. It poses significant risks if malicious actors leverage this flaw, compromising data integrity and confidentiality. Proper access control measures must be enforced to mitigate these risks.
Affected Version(s)
Kibana 9.4.0 <= 9.4.2