GHSA-2529-45pr-jcrgMediumCVSS 4.3

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized...

Published
July 21, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.

🔗 References (3)