Vulnerability  ·  2026-09-27

Kibana Agent Builder 'confused deputy' privilege escalation to full Kibana/Elasticsearch admin (CVE-2026-72668)

VulnerabilityHigh impactGlobalCVE-2026-72668
Elastic ESA-2026-85 (2026-09-25) fixed CVE-2026-72668 (CVSS 7.3): the Agent Builder + Workflows combination introduced in 9.4.0 lets a low-privileged user cause a higher-privileged user's agent interaction to execute privileged work. Fixed in Kibana 9.4.7/9.5.0; Elastic Cloud Serverless was remediated pre-disclosure.
The confusion-deputy pattern in an agent runtime means the agentic layer itself becomes a privilege-escalation bridge across the identity boundary — a non-admin edits an agent that then acts with admin power when an admin touches it. For AI deployments, treat agent configuration as privileged data and disable Workflows if it isn't needed until 9.4.7/9.5.0 is applied.
A non-administrative user with Agent Builder privilege edits a shared agent; when a higher-privileged user later interacts with that agent, privileged operations are carried out under the privileged user's identity (unintended proxy/confused deputy). If the same attacker can author workflows, escalation extends to full administrative control of Kibana and the Elasticsearch cluster.
Upgrade Kibana to 9.4.7 or 9.5.0; interim: disable the Workflows feature and review/remove non-admin-authored workflows attached to agents.
Elastic ESA-2026-85 (Kibana 9.4.7/9.5.0)NVD - CVE-2026-72668
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →