Elastic Fixes 14 Security Flaws Including One That Lets Attackers Intercept Other Users’ Data
Elastic patched 14 flaws, including a CVSS 8.8 Kibana bug letting Fleet users intercept other tenants' data.
Elastic published 14 advisories for Elasticsearch, Kibana, and Elastic Agent/Endpoint. The most serious, CVE-2026-102406 (CVSS 8.8), lets a delegated Fleet user with custom-package install rights claim another tenant's data stream identifier and apply attacker-controlled index and ingest-pipeline settings, intercepting or modifying newly ingested data. Affected Kibana ranges are 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, fixed in 8.19.22, 9.4.7, and 9.5.4. Other fixes cover CVE-2026-103009 (CVSS 7.1) cross-cluster search authorization bypass, two CVSS 6.5 Elasticsearch denial-of-service flaws, and Elastic Endpoint CVE-2026-102413 (CVSS 6.2).