What happened
Published 2026-09-26 (CVSS 7.3): an unintended-proxy / confused-deputy flaw in Kibana's Agent Builder lets a low-privilege editor weaponize a shared agent to execute privileged operations under a powerful user's identity.
Why it matters
Kibana's Agent Builder is where elastic-agent-based AI assistants and synthetic-monitoring agents are configured; this is an agent-configuration attack where identity delegation in the agent runtime is the escalation primitive reaching the Elasticsearch data plane.
Attack vector
CWE-441 confused-deputy: a non-administrative user edits a shared agent so that privileged operations run under the identity of a higher-privileged user who subsequently interacts with that agent; where the attacker can also author workflows, this escalates to full admin control of Kibana and the ES cluster.
Affected systems
Elastic Kibana 9.4.0 through 9.4.6 (Agent Builder). Fixed in 9.4.7 / 9.5.0 (ESA-2026-85).
Mitigation
Upgrade to Kibana 9.4.7 or 9.5.0 (ESA-2026-85).