Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 22, 2026
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
CVE-2026-49092
Description
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Affected products
4- osv-coords2 versions
>= 9.4.0, < 9.4.3+ 1 more
- (no CPE)range: >= 9.4.0, < 9.4.3
- (no CPE)range: >= 9.4.0, < 9.4.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.