Unintended Proxy or Intermediary in Kibana - CVE-2026-49092
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an unintended proxy or intermediary (confused deputy) in Entity Analytics when processing functionality not properly constrained by access controls. A remote user can trigger processing of data using another user's privileges to disclose sensitive information.
Only deployments with Entity Analytics enabled are vulnerable.