Elastic Fixes 14 Security Flaws Including One That Lets Attackers Intercept Other Users’ Data
Elastic patched 14 flaws, including a CVSS 8.8 Kibana bug letting Fleet users intercept other tenants' data.
Elastic published 14 advisories for Elasticsearch, Kibana, and Elastic Agent/Endpoint. The most serious, CVE-2026-102406 (CVSS 8.8), lets a delegated Fleet user with custom-package install rights claim another tenant's data stream identifier and apply attacker-controlled index and ingest-pipeline settings, intercepting or modifying newly ingested data. Affected Kibana ranges are 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, fixed in 8.19.22, 9.4.7, and 9.5.4. Other fixes cover CVE-2026-103009 (CVSS 7.1) cross-cluster search authorization bypass, two CVSS 6.5 Elasticsearch denial-of-service flaws, and Elastic Endpoint CVE-2026-102413 (CVSS 6.2).
- CVE-2026-102406 (CVSS 8.8) lets delegated Fleet users hijack another tenant's data stream.
- Attackers can apply malicious index and ingest-pipeline settings and intercept ingested data.
- Package removal is not enough; administrators must inspect and repair affected infrastructure.
- Fixes are in Kibana 8.19.22, 9.4.7, and 9.5.4; restrict custom package uploads until patched.
- Additional high and medium flaws include cross-cluster search authorization bypass and Elasticsearch DoS issues.
Vulnerabilities mentionedAll →
- CVE-2026-1030097.1—Authorization bypass in Elasticsearch cross-cluster searchpublished · Elasticsearch+2 related
- CVE-2026-1024068.8—Kibana Fleet authorization bypass allows cross-tenant interceptionpublished · Elastic Kibana
Full article449 words · extracted from cybersecuritynews.com · click to collapse
Elastic published 14 security advisories covering Elasticsearch, Kibana, and Elastic Agent/Endpoint, including a high-severity Kibana flaw that lets delegated Fleet users intercept data from other users or teams.
Tracked as CVE-2026-102406, the Kibana flaw carries a CVSS score of 8.8. It affects Fleet’s package installation process, which failed to verify ownership before applying uploaded integration settings to an existing data stream.
An attacker with permission to install custom Fleet packages could claim a data stream identifier already used by another tenant, without needing direct Elasticsearch administrative privileges.
Fleet could then apply the attacker’s index and ingest-pipeline settings to existing infrastructure. This allowed newly ingested information to pass through infrastructure controlled by the attacker, exposing it to unauthorized access and modification while stopping delivery to its intended destination.
Elastic warned that interception could continue after removal of the malicious package. Administrators must therefore examine and separately repair affected infrastructure rather than treating package removal as complete remediation.
Elastic Fixes 14 Security Flaws
Here, “tenant” means users or teams within one Kibana deployment, not separate Elastic Cloud customers. The issue affects Kibana versions 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3.
Fixes arrived in 8.19.22, 9.4.7, and 9.5.4. Both self-managed and Elastic Cloud Hosted installations are affected when delegated users can upload custom integration packages. Another high-severity flaw, CVE-2026-103009, scores 7.1 and affects cross-cluster search using Remote Cluster Security 2.0.
A specially crafted request can pass authorization against an allowed index while accessing a different, unauthorized index, exposing documents, mappings, and metadata. It requires access through the remote cluster transport interface and cannot be exploited through the REST API.
Elasticsearch also received fixes for denial-of-service weaknesses. CVE-2026-103008 allows an authenticated user with index read access to trigger excessive recursion through scripted geometry, terminating a node.
CVE-2026-102404 permits crafted ES|QL queries to exhaust memory and repeatedly disrupt cluster availability. Both carry CVSS scores of 6.5 and are fixed in 8.19.23, 9.4.8, and 9.5.5.
Elastic Endpoint’s CVE-2026-102413, rated 6.2, can cause repeated crashes when processing crafted filenames under certain Windows locales, including Chinese, Japanese, and Korean. These crashes can weaken or turn off malware prevention and behavioral detection.
Administrators should install the applicable fixed releases and review upgrade notes. Until Kibana is patched, Elastic recommends restricting custom package uploads to full superusers.
Investigators should review uploaded Fleet packages for reused datasets and unexpected changes to existing ingest pipelines. Elastic remediated the Kibana flaw in Cloud Serverless before disclosure.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.