Skip to content

Elastic Fixes 14 Security Flaws Including One That Lets Attackers Intercept Other Users’ Data

Cybersecuritynews •Abinaya • October 8, 2026

Elastic published 14 security advisories covering Elasticsearch, Kibana, and Elastic Agent/Endpoint, including a high-severity Kibana flaw that lets delegated Fleet users intercept data from other users or teams. Tracked as CVE-2026-102406, the Kibana flaw carries a CVSS score of 8.8. It affects Fleet’s package installation process, which failed to verify ownership before applying uploaded integration […]

Extracted Entities