Skip to content
Elastic Addresses 14 Security Flaws, High-Severity Kibana Vulnerability Disclosed

Elastic Addresses 14 Security Flaws, High-Severity Kibana Vulnerability Disclosed

First seen 8 Oct 2026, 07:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 08:32 UTC
  • •A high-severity Kibana vulnerability allows data interception between tenants.
  • •Fourteen vulnerabilities were patched, affecting Elasticsearch, Kibana, and Elastic Agent/Endpoint.
  • •Specific versions are vulnerable, requiring targeted upgrades to address the issues.

Elastic released 14 security advisories for vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. A Kibana flaw, CVE-2026-102406, with a CVSS score of 8.8, allows attackers to intercept data from other users due to a package management oversight. This flaw affects versions 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, with fixes available in 8.19.22, 9.4.7, and 9.5.4. Other vulnerabilities include CVE-2026-103009 (7.1), CVE-2026-102404 (6.5), CVE-2026-103008 (6.5), and CVE-2026-102413 (6.2), impacting various functionalities and potentially leading to denial-of-service conditions. Users are advised to upgrade their systems to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
CVE-2026-102406 published
Elastic disclosed a high-severity Kibana flaw allowing data interception due to package management issues.
Gbhackers
2026-10-06
CVE-2026-103009 published
Elastic reported another vulnerability in Elasticsearch related to inconsistent shard identification during requests.
Gbhackers
2026-10-06
CVE-2026-102404 published
Elastic disclosed a vulnerability that could lead to denial-of-service through crafted ES|QL queries.
Gbhackers
2026-10-06
CVE-2026-102413 published
Elastic announced a flaw in Elastic Endpoint affecting Windows protection capabilities.
Gbhackers
2026-10-06
CVE-2026-103008 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-102404 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Kibana versions 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3 are affected.
What is the severity of the Kibana vulnerability?
CVE-2026-102406 has a CVSS score of 8.8, indicating high severity.
What should users do to protect themselves?
Users should upgrade to the patched versions 8.19.22, 9.4.7, and 9.5.4 to mitigate these vulnerabilities.