Gbhackers Elastic Addresses 14 Security Flaws, High-Severity Kibana Vulnerability Disclosed
Article Content
- •A high-severity Kibana vulnerability allows data interception between tenants.
- •Fourteen vulnerabilities were patched, affecting Elasticsearch, Kibana, and Elastic Agent/Endpoint.
- •Specific versions are vulnerable, requiring targeted upgrades to address the issues.
Elastic released 14 security advisories for vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. A Kibana flaw, CVE-2026-102406, with a CVSS score of 8.8, allows attackers to intercept data from other users due to a package management oversight. This flaw affects versions 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, with fixes available in 8.19.22, 9.4.7, and 9.5.4. Other vulnerabilities include CVE-2026-103009 (7.1), CVE-2026-102404 (6.5), CVE-2026-103008 (6.5), and CVE-2026-102413 (6.2), impacting various functionalities and potentially leading to denial-of-service conditions. Users are advised to upgrade their systems to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-102404 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
What is the severity of the Kibana vulnerability?
What should users do to protect themselves?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…