Elastic Fixes 14 Security Flaws Including One That Lets Attackers Intercept Other Users’ Data
Elastic published 14 security advisories covering Elasticsearch, Kibana, and Elastic Agent/Endpoint, including a high-severity Kibana flaw that lets delegated Fleet users intercept data from other users or teams. Tracked as CVE-2026-102406, the Kibana flaw carries a CVSS score of 8.8. It affects Fleet’s package installation process, which failed to verify ownership before applying uploaded integration […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
