Junglewise Threat Intelligence

CVE-2026-49092: Elastic Kibana confused deputy in Entity Analytics

CVE-2026-49092 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

A security vulnerability exists in Kibana, a popular data visualization and management platform, specifically when the Entity Analytics feature is enabled. An authenticated user with low-level permissions can trick the system into accessing or processing data they are not authorized to see by leveraging the higher privileges of another user. This could lead to the unauthorized exposure of sensitive internal data, though it does not allow for the modification or deletion of that information.

Technical details

A Confused Deputy vulnerability (CWE-441) exists in Elastic Kibana versions 9.4.0 through 9.4.2 when Entity Analytics is enabled. The flaw stems from incorrect authorization (CWE-863) where functionality is not properly constrained by Access Control Lists (ACLs). An authenticated attacker with low privileges can trigger processes that access data sources using the privileges of a different, higher-privileged user or service account. This results in unauthorized information exposure (CAPEC-1). The issue is resolved in Kibana version 9.4.3; no workarounds are available for affected versions.

Affected products

  • Elastic Kibana 9.4.0 to 9.4.2

Timeline

  • 2026-07-21: advisory: Elastic security update ESA-2026-54 published
  • 2026-07-21: patched: Remediated in Kibana version 9.4.3

References

Related threats