SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-49092

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana is vulnerable due to a misconfiguration that allows lower-privileged users to access data they should not be authorized to view, leveraging another user's privileges. This flaw can lead to unauthorized information exposure, posing a risk to data confidentiality. Organizations using Kibana should prioritize addressing this vulnerability to safeguard sensitive information from potential leaks.

CVE
CVE-2026-49092
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.

Related CVEs

Other vulnerabilities affecting the same vendor(s)