Vulnerability  ·  2026-09-27

Kibana Agent Builder confused-deputy privilege escalation can reach full Elasticsearch cluster control (CVE-2026-72668)

VulnerabilityMedium impactGlobalCVE-2026-72668
Published 2026-09-26 (CVSS 7.3): an unintended-proxy / confused-deputy flaw in Kibana's Agent Builder lets a low-privilege editor weaponize a shared agent to execute privileged operations under a powerful user's identity.
Kibana's Agent Builder is where elastic-agent-based AI assistants and synthetic-monitoring agents are configured; this is an agent-configuration attack where identity delegation in the agent runtime is the escalation primitive reaching the Elasticsearch data plane.
CWE-441 confused-deputy: a non-administrative user edits a shared agent so that privileged operations run under the identity of a higher-privileged user who subsequently interacts with that agent; where the attacker can also author workflows, this escalates to full admin control of Kibana and the ES cluster.
Elastic Kibana 9.4.0 through 9.4.6 (Agent Builder). Fixed in 9.4.7 / 9.5.0 (ESA-2026-85).
Upgrade to Kibana 9.4.7 or 9.5.0 (ESA-2026-85).
NVD — CVE-2026-72668Elastic — Kibana 9.4.7 / 9.5.0 security update ESA-2026-85
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →