Skip to content
Elastic Patches 14 Security Flaws, Including One Enabling Cross

Elastic Patches 14 Security Flaws, Including One Enabling Cross

Gbhackers •Divya • October 7, 2026

Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint.

Among these, a high-severity Kibana authorization bypass vulnerability allows for cross-tenant data interception. Other issues include information disclosure and denial-of-service weaknesses in Elasticsearch, along with a flaw in Elastic Endpoint that affects Windows protection capabilities.

The advisory list consists of ten Elasticsearch advisories, three Kibana advisories, and one Elastic Agent/Endpoint advisory.

Each advisory pertains to specific affected version ranges, highlighting the need for product-specific upgrade checks rather than assuming a single patch level resolves all deployment exposures.

Elastic Patches 14 Security Flaws

The Kibana vulnerability, tracked as CVE-2026-102406, has a CVSS score of 8.8 and results from an authorization bypass through a user-controlled key, classified as CWE-639.

Elastic clarified that “tenant” refers to users or teams sharing one Kibana deployment, not separate Elastic Cloud customers or organizations.

An attacker with delegated Fleet package-management privileges could upload a custom integration package that claims a data stream identifier belonging to another tenant.

The Fleet system failed to verify ownership before applying the generated index and ingest-pipeline settings to the existing infrastructure. Direct administrative privileges in Elasticsearch were not necessary for exploitation.

This vulnerability allowed attackers to redirect ingested data through infrastructure they controlled, potentially exposing it to unauthorized disclosure and modification while preventing delivery to the correct destination.

Notably, interception could persist even after the malicious package was removed, necessitating separate remediation of the affected infrastructure.

Affected versions include Kibana 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3. Fixes have been released in 8.19.22, 9.4.7, and 9.5.4. Both self-managed and Elastic Cloud Hosted deployments with the relevant Fleet permissions are vulnerable.

The Elasticsearch vulnerability CVE-2026-103009, rated 7.1, involves inconsistent shard identification during cross-cluster requests using Remote Cluster Security 2.0.

An API key authorized for one index could access another index’s documents, mappings, and metadata. This issue requires exposure of the remote cluster transport interface and cannot be exploited through the REST API .

Two availability flaws include CVE-2026-103008, which involves deeply nested scripted geometry that exhausts stack space, and CVE-2026-102404, where crafted ES|QL queries trigger uncontrolled memory allocation.

Both vulnerabilities score 6.5 and can terminate Elasticsearch nodes. Fixes for these issues are available in versions 8.19.23, 9.4.8, and 9.5.5.

For Elastic Endpoint, CVE-2026-102413, rated 6.2, allows specially crafted filenames to trigger repeated crashes in certain Windows locales, including Chinese, Japanese, and Korean. This could degrade or turn off real-time malware prevention and behavioral detection.

Administrators should prioritize upgrades and review uploaded Fleet package histories for reused datasets and unexpected changes in ingest pipelines. Until patching is complete, restrict custom package uploads to trusted superusers.

Elastic remediated the Kibana flaw in Serverless before its disclosure. Endpoint fixes require versions 8.19.22, 9.4.8, or 9.5.5; users still on the affected 9.2.x and 9.3.x lines must migrate to a supported release line.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .

Artificial Intelligence

Cyber security Course

Cyber Security Resources

Cybersecurity

Information Gathering

Information Security Risks

Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands

Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure

FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials

Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches

OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack

LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension