AI analysis
CVE-2026-102406 is an authorization bypass through a user-controlled key (CWE-639) in Kibana's Fleet package installation process. A user who holds delegated Fleet package-management privileges, but not direct Elasticsearch administrative privileges, can claim a data stream identifier already in use by another tenant on the same Kibana deployment, and Fleet applies the uploaded package's generated index and ingest-pipeline settings without verifying ownership. The attacker can redirect that tenant's data stream through infrastructure they control, so subsequently ingested data can be disclosed or modified and does not reach its intended destination. It affects users or teams sharing one Kibana deployment, not separate Elastic Cloud organizations, and interception can continue after the malicious package is removed until the affected infrastructure is remediated separately. No public proof of concept is known, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply the fixed Kibana release from Elastic's advisory for CVE-2026-102406 as soon as it is identified; no patched version range was included in the supplied data. Until then, limit who can hold delegated Fleet package-management privileges and audit data-stream identifiers, index settings, and ingest pipelines for claims or rewrites made by a package a delegated user installed. Removing the package is not enough: separately restore ownership and routing of affected data streams so ingestion returns to the intended destination, and review logs for disclosure or modification of another tenant's data.
Estimated exposure
largeOn the order of 10,000–100,000 Kibana deployments potentially relevant; exact count unknown — Kibana is a core part of the widely deployed Elastic Stack, and public internet scans have long shown on the order of tens of thousands of reachable instances, with many more only on internal networks. Only shared multi-tenant deployments…
Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, to claim a data stream identifier already in use by another tenant. Because ownership of that identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, an attacker could redirect an existing tenant's data stream through infrastructure under their control. This exposed the affected tenant's subsequently ingested data to unauthorized disclosure and modification, and prevented that data from reaching its intended destination. Interception could continue even after the malicious package was removed, requiring separate remediation of the affected infrastructure.