CVE-2026-49092: Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49092?
The severity of CVE-2026-49092 is medium, with a score of 4.3.
How does CVE-2026-49092 affect Kibana?
CVE-2026-49092 affects Kibana by allowing unauthorized users to access data they should not see due to improper access control mechanisms.
What type of exposure does CVE-2026-49092 cause?
CVE-2026-49092 leads to unauthorized information exposure through unintended proxy behavior.
How can CVE-2026-49092 be mitigated?
To mitigate CVE-2026-49092, ensure that access control lists (ACLs) are properly defined and enforced.
Who is at risk from CVE-2026-49092?
Lower-privileged users are at risk from CVE-2026-49092 as they can exploit it to access restricted data.