Elastic patches 14 flaws; Canada lists different versions
Elastic patched 14 flaws led by CVSS 8.8 Kibana CVE-2026-102406; Canada’s advisory lists different version cutoffs.
Elastic published 14 advisories for Elasticsearch, Kibana, and Elastic Agent/Endpoint, led by Kibana CVE-2026-102406 (CVSS 8.8). Two reports agree the affected Kibana ranges are 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, fixed in 8.19.22, 9.4.7, and 9.5.4, but they differ on the flaw: one says Fleet package-management rights can claim another tenant’s data stream and redirect ingested data, and quotes Elastic that tenant means users of one deployment rather than separate Elastic Cloud customers; the other says a delegated user with custom-package install rights can set index and ingest-pipeline options to intercept or modify newly ingested data. Both say removing the package is not enough because the effect can persist. Other fixes include CVE-2026-103009 (CVSS 7.1), framed as remote-cluster cross-index access or a cross-cluster search bypass; two CVSS 6.5 Elasticsearch bugs that can crash nodes via scripts or ES|QL; and Endpoint CVE-2026-102413, scored 6.2 by one source and tied by the other to disabling Windows malware prevention with crafted filenames, while that source’s summary also mentions a Windows Endpoint crash. On 8 October 2026 Canada’s Cyber Centre issued AV26-1021, citing ESA-2026-185 and ESA-2026-187 and listing Elasticsearch through 8.19.23, 9.4.8, and 9.5.5 and Kibana through 8.19.22, 9.4.7, and 9.5.4 as affected as of 6 October—cutoffs that disagree with the fixed versions above—and it does not report exploitation.
- Elastic published 14 advisories for Elasticsearch, Kibana, and Elastic Agent/Endpoint.
- CVE-2026-102406 (CVSS 8.8) is a Kibana authorization bypass; two reports give affected ranges 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3, fixed in 8.19.22, 9.4.7, and 9.5.4.
- Those reports disagree on access and impact: Fleet package-management rights and data-stream redirection versus custom-package install rights that set index and ingest-pipeline options and can intercept or modify new data. One cites…
- Both say the effect can persist after the package is removed; one says administrators must inspect and repair and should restrict custom package uploads until patched.
- CVE-2026-103009 (CVSS 7.1) is described as remote-cluster cross-index access or a cross-cluster search authorization bypass. Two CVSS 6.5 Elasticsearch flaws can crash nodes via scripts or ES|QL.
- Endpoint CVE-2026-102413 is scored CVSS 6.2 in one report and linked by the other to disabling Windows malware prevention via crafted filenames; that report’s summary also calls it a Windows Endpoint crash. The same two reports also list…
Coverage timelineoldest first · each row is one article
- · 1d agoElastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
GBHackers· 66
Elastic patched 14 flaws, including a Kibana bypass that can intercept another tenant's data.
- · 21h agoElastic Fixes 14 Security Flaws Including One That Lets Attackers Intercept Other Users’ Data
Cyber Security News· 64
Elastic patched 14 flaws, including a CVSS 8.8 Kibana bug letting Fleet users intercept other tenants' data.
- · 10h agoElastic security advisory (AV26-1021)
Canadian Centre for Cyber Security· 36
Vulnerabilities in this storyAll →
- CVE-2026-1030097.1—Authorization bypass in Elasticsearch cross-cluster searchpublished · Elasticsearch+2 related
- CVE-2026-1024068.8—Kibana Fleet authorization bypass allows cross-tenant interceptionpublished · Elastic Kibana