Elastic security advisory (AV26-1021)
Canada's Cyber Centre warns Elasticsearch and Kibana users to install Elastic updates ESA-2026-185 and ESA-2026-187.
The Canadian Centre for Cyber Security published advisory AV26-1021 on October 8, 2026, stating that as of October 6 Elasticsearch and Kibana were affected by vulnerabilities. Elasticsearch versions prior to or equal to 8.19.23, 9.4.8, and 9.5.5, and Kibana versions prior to or equal to 8.19.22, 9.4.7, and 9.5.4, are listed. Elastic’s related announcements are ESA-2026-185 for Elasticsearch and ESA-2026-187 for Kibana. The centre urges administrators to review the notices and apply updates; the advisory does not report exploitation.
- AV26-1021, dated October 8, 2026, flags Elasticsearch and Kibana vulnerabilities.
- Elasticsearch branches through 8.19.23, 9.4.8, and 9.5.5 are listed as affected.
- Kibana branches through 8.19.22, 9.4.7, and 9.5.4 are listed as affected.
- Updates are ESA-2026-185 and ESA-2026-187; exploitation is not mentioned.
Full article114 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1021
Date: October 8, 2026
As of October 6, 2026, Elastic is affected by vulnerabilities in the following products:
- Elasticsearch
- Prior to or equal to 8.19.23
- Prior to or equal to 9.4.8
- Prior to or equal to 9.5.5
- Kibana
- Prior to or equal to 8.19.22
- Prior to or equal to 9.4.7
- Prior to or equal to 9.5.4
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/elastic-security-advisory-av26-1021