Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
Elastic patched 14 flaws, including a Kibana bypass that can intercept another tenant's data.
Elastic published 14 advisories for Elasticsearch, Kibana, and Elastic Agent/Endpoint. CVE-2026-102406 (CVSS 8.8) is a Kibana authorization bypass that lets a user with Fleet package-management rights claim another tenant's data stream and redirect ingested data; Elastic says tenant means users sharing one deployment, not separate Elastic Cloud customers. Affected Kibana ranges are 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, fixed in 8.19.22, 9.4.7, and 9.5.4. Other fixes cover Elasticsearch cross-cluster data access (CVE-2026-103009), two denial-of-service bugs, and an Elastic Endpoint crash on Windows.
- CVE-2026-102406 (CVSS 8.8) lets Fleet managers intercept another Kibana tenant's data.
- Interception can persist after the malicious integration package is removed.
- CVE-2026-103009 (CVSS 7.1) allows cross-index access over remote cluster transport.
- Two Elasticsearch flaws (CVSS 6.5) can crash nodes via scripts or ES|QL.
- Elastic Endpoint CVE-2026-102413 can disable Windows malware prevention via crafted filenames.
Vulnerabilities mentionedAll →
- CVE-2026-1030097.1—Authorization bypass in Elasticsearch cross-cluster searchpublished · Elasticsearch+2 related
- CVE-2026-1024068.8—Kibana Fleet authorization bypass allows cross-tenant interceptionpublished · Elastic Kibana
Full article504 words · extracted from gbhackers.com · click to collapse
Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint.
Among these, a high-severity Kibana authorization bypass vulnerability allows for cross-tenant data interception. Other issues include information disclosure and denial-of-service weaknesses in Elasticsearch, along with a flaw in Elastic Endpoint that affects Windows protection capabilities.
The advisory list consists of ten Elasticsearch advisories, three Kibana advisories, and one Elastic Agent/Endpoint advisory.
Each advisory pertains to specific affected version ranges, highlighting the need for product-specific upgrade checks rather than assuming a single patch level resolves all deployment exposures.
Elastic Patches 14 Security Flaws
The Kibana vulnerability, tracked as CVE-2026-102406, has a CVSS score of 8.8 and results from an authorization bypass through a user-controlled key, classified as CWE-639.
Elastic clarified that “tenant” refers to users or teams sharing one Kibana deployment, not separate Elastic Cloud customers or organizations.
An attacker with delegated Fleet package-management privileges could upload a custom integration package that claims a data stream identifier belonging to another tenant.
The Fleet system failed to verify ownership before applying the generated index and ingest-pipeline settings to the existing infrastructure. Direct administrative privileges in Elasticsearch were not necessary for exploitation.
This vulnerability allowed attackers to redirect ingested data through infrastructure they controlled, potentially exposing it to unauthorized disclosure and modification while preventing delivery to the correct destination.
Notably, interception could persist even after the malicious package was removed, necessitating separate remediation of the affected infrastructure.
Affected versions include Kibana 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3. Fixes have been released in 8.19.22, 9.4.7, and 9.5.4. Both self-managed and Elastic Cloud Hosted deployments with the relevant Fleet permissions are vulnerable.
The Elasticsearch vulnerability CVE-2026-103009, rated 7.1, involves inconsistent shard identification during cross-cluster requests using Remote Cluster Security 2.0.
An API key authorized for one index could access another index’s documents, mappings, and metadata. This issue requires exposure of the remote cluster transport interface and cannot be exploited through the REST API.
Two availability flaws include CVE-2026-103008, which involves deeply nested scripted geometry that exhausts stack space, and CVE-2026-102404, where crafted ES|QL queries trigger uncontrolled memory allocation.
Both vulnerabilities score 6.5 and can terminate Elasticsearch nodes. Fixes for these issues are available in versions 8.19.23, 9.4.8, and 9.5.5.
For Elastic Endpoint, CVE-2026-102413, rated 6.2, allows specially crafted filenames to trigger repeated crashes in certain Windows locales, including Chinese, Japanese, and Korean. This could degrade or turn off real-time malware prevention and behavioral detection.
Administrators should prioritize upgrades and review uploaded Fleet package histories for reused datasets and unexpected changes in ingest pipelines. Until patching is complete, restrict custom package uploads to trusted superusers.
Elastic remediated the Kibana flaw in Serverless before its disclosure. Endpoint fixes require versions 8.19.22, 9.4.8, or 9.5.5; users still on the affected 9.2.x and 9.3.x lines must migrate to a supported release line.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.