TL;DR
Elastic has published 14 security advisories covering Elasticsearch, Kibana and Elastic Defend. Three of these Elastic Stack vulnerabilities rate High, led by a Kibana Fleet flaw with a CVSS score of 8.8. Admins should move to Elasticsearch 8.19.23, 9.4.8 or 9.5.5 and the matching Kibana and Agent releases.
- Total: 14 CVEs
- Severity: 3 High · 11 Medium
- Actively exploited: None confirmed
- Highest severity: 8.8 (High · CVSSv3) — CVE-2026-102406
- Action: Apply the latest security updates now
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-102406 | 8.8 | CWE-639 | Not exploited |
| CVE-2026-103007 | 7.2 | CWE-863 | Not exploited |
| CVE-2026-103009 | 7.1 | CWE-639 | Not exploited |
| CVE-2026-103008 | 6.5 | CWE-674 | Not exploited |
| CVE-2026-103006 | 6.5 | CWE-674 | Not exploited |
| CVE-2026-103005 | 6.5 | CWE-789 | Not exploited |
| CVE-2026-102412 | 6.5 | CWE-863 | Not exploited |
| CVE-2026-102411 | 6.5 | CWE-770 | Not exploited |
Why It Matters
Elasticsearch and Kibana power search, logging and security monitoring at many organizations. Shared clusters often hold data from many teams. As a result, a bug that crosses team boundaries can expose sensitive records.
Nearly every flaw requires a logged-in user, so outside attackers would need valid accounts first. Elastic’s advisories list the exploitation status as unknown. No attacks in the wild or public proof-of-concept code have been confirmed.
How the Attacks Work
Kibana Fleet Data Hijack (CVE-2026-102406)
The top-rated bug sits in Kibana’s Fleet package installer. A user with delegated package rights could claim a data stream already owned by another team. Elastic warns that “an attacker could redirect an existing tenant’s data stream through infrastructure under their control.” Worse, “interception could continue even after the malicious package was removed.”
Privilege Escalation (CVE-2026-103007)
This Elasticsearch flaw, rated 7.2, affects a non-default delegated role-management privilege. A user holding it could edit their own role to reach restricted indices. According to Elastic, this “can enable further escalation up to full administrative control of the cluster.”
Cross-Cluster Data Exposure (CVE-2026-103009)
Rated 7.1, this bug affects cross-cluster search. The authorization check and the actual data lookup rely on two different shard attributes. Consequently, a key holder can read an index they should not reach.
Denial of Service and Other Bugs
Eight of the 14 Elastic Stack vulnerabilities allow denial of service. Several involve deeply nested requests or memory exhaustion that can crash a node. For CVE-2026-103006, Elastic notes that “the node does not recover automatically and requires manual intervention to restore service.” Separately, CVE-2026-102413 can crash Elastic Defend on Windows hosts that use Chinese, Japanese or Korean locales. That crash can weaken malware protection while it lasts.
Another Kibana bug, CVE-2026-102412, lets a user with limited Fleet rights read private keys used for Fleet Server connections.
Affected Versions
Affected ranges differ by flaw. Most hit Elasticsearch 8.x through 8.19.22, 9.4.7 and 9.5.4. One data stream bug reaches back to 7.17.5. Kibana flaws span 8.14.0 through 9.5.3, depending on the issue.
Patch and Mitigation Steps
Upgrade Elasticsearch to 8.19.23, 9.4.8 or 9.5.5. Update Kibana and Elastic Agent to the fixed releases on the same branches. Each fix is listed in the Elastic security announcements.
Meanwhile, review who holds Fleet package rights and delegated role-management privileges. Those roles open the door to the most serious Elastic Stack vulnerabilities in this batch.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!