Unintended Proxy or Intermediary in Kibana - CVE-2026-72668
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to an unintended proxy or intermediary ('confused deputy') in Kibana Agent Builder when a higher-privileged user interacts with an agent edited by a non-administrative user. A remote user can edit a shared agent and create workflows to escalate privileges.
A generative AI connector must be configured for Agent Builder.