Medium severity4.3NVD Advisory· Published Jul 21, 2026· Updated Aug 6, 2026
CVE-2026-49092
CVE-2026-49092
Description
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords2 versions
>= 9.4.0, < 9.4.3+ 1 more
- (no CPE)range: >= 9.4.0, < 9.4.3
- (no CPE)range: >= 9.4.0, < 9.4.3
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553nvdVendor Advisory
News mentions
0No linked articles in our index yet.