Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
Elastic patched 14 flaws, including a Kibana bypass that can intercept another tenant's data.
Elastic published 14 advisories for Elasticsearch, Kibana, and Elastic Agent/Endpoint. CVE-2026-102406 (CVSS 8.8) is a Kibana authorization bypass that lets a user with Fleet package-management rights claim another tenant's data stream and redirect ingested data; Elastic says tenant means users sharing one deployment, not separate Elastic Cloud customers. Affected Kibana ranges are 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, fixed in 8.19.22, 9.4.7, and 9.5.4. Other fixes cover Elasticsearch cross-cluster data access (CVE-2026-103009), two denial-of-service bugs, and an Elastic Endpoint crash on Windows.