
🚨High - Kibana Agent Builder Confused-Deputy Privilege Escalation (CVE-2026-72668) Kibana Agent Builder lets a non-admin who can edit a shared agent craft actions that execute when a higher-privileged user later runs/interacts with the agent, causing privileged operations under that user’s identity. If the attacker can also author workflows, this can escalate to full Kibana + Elasticsearch cluster admin control. 👉Affected: Kibana (versions not specified)
