Executive brief
Kibana is a data visualization and management platform for the Elastic Stack. A security flaw allows users with low-level permissions to access the results of automated workflows they are not authorized to see. This could lead to the exposure of sensitive data retrieved from connected corporate databases or internal systems.
Technical details
A missing authorization vulnerability (CWE-862) exists in Kibana's Workflows Management feature. The flaw allows an authenticated user with limited feature privileges (specifically 'agentBuilder:all') to access workflow execution outputs in their Kibana space without possessing the required 'workflowsManagement:readExecution' privilege. This access is possible via the API and can expose sensitive information returned by workflow steps, including data from connected sources that the user is otherwise restricted from viewing. The vulnerability affects Enterprise license deployments where both Agent Builder and Workflows Management are enabled. It is fixed in Kibana versions 9.3.8 and 9.4.4.
Affected products
- Elastic Kibana 9.3.0 to 9.3.7, 9.4.0 to 9.4.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
- 2026-07-21: patched