Executive brief
Kibana, a data visualization and analytics platform for Elasticsearch, contains a privilege escalation flaw in its Agent Builder component. A non-administrative user with limited permissions can manipulate a shared agent to trick higher-privileged users into executing administrative operations. In environments where the attacker also has workflow creation capabilities, this can lead to complete control over Kibana and the underlying Elasticsearch cluster.
Technical details
This is a confused deputy vulnerability (CWE-441) in Kibana's Agent Builder that allows privilege escalation through malicious agent configuration. An authenticated, non-administrative user with Agent Builder and Workflows privileges can modify shared agents to execute operations with the privileges of a higher-privileged user who subsequently interacts with the agent, potentially gaining administrative control of both Kibana and Elasticsearch. The vulnerability requires a generative AI connector to be configured and affects versions 9.4.0 through 9.4.6; it can be mitigated by disabling the Workflows feature.
Affected products
- Elastic Kibana 9.4.0 through 9.4.6
Timeline
- 2026-09-26: disclosed