Cyber Security News

Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception

Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint.

Among these, a high-severity Kibana authorization bypass vulnerability allows for cross-tenant data interception. Other issues include information disclosure and denial-of-service weaknesses in Elasticsearch, along with a flaw in Elastic Endpoint that affects Windows protection capabilities.

The advisory list consists of ten Elasticsearch advisories, three Kibana advisories, and one Elastic Agent/Endpoint advisory.

Each advisory pertains to specific affected version ranges, highlighting the need for product-specific upgrade checks rather than assuming a single patch level resolves all deployment exposures.

Elastic Patches 14 Security Flaws

The Kibana vulnerability, tracked as CVE-2026-102406, has a CVSS score of 8.8 and results from an authorization bypass through a user-controlled key, classified as CWE-639.

Elastic clarified that “tenant” refers to users or teams sharing one Kibana deployment, not separate Elastic Cloud customers or organizations.

An attacker with delegated Fleet package-management privileges could upload a custom integration package that claims a data stream identifier belonging to another tenant.

The Fleet system failed to verify ownership before applying the generated index and ingest-pipeline settings to the existing infrastructure. Direct administrative privileges in Elasticsearch were not necessary for exploitation.

This vulnerability allowed attackers to redirect ingested data through infrastructure they controlled, potentially exposing it to unauthorized disclosure and modification while preventing delivery to the correct destination.

Notably, interception could persist even after the malicious package was removed, necessitating separate remediation of the affected infrastructure.

Affected versions include Kibana 8.14.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3. Fixes have been released in 8.19.22, 9.4.7, and 9.5.4. Both self-managed and Elastic Cloud Hosted deployments with the relevant Fleet permissions are vulnerable.

The Elasticsearch vulnerability CVE-2026-103009, rated 7.1, involves inconsistent shard identification during cross-cluster requests using Remote Cluster Security 2.0.

An API key authorized for one index could access another index’s documents, mappings, and metadata. This issue requires exposure of the remote cluster transport interface and cannot be exploited through the REST API.

Two availability flaws include CVE-2026-103008, which involves deeply nested scripted geometry that exhausts stack space, and CVE-2026-102404, where crafted ES|QL queries trigger uncontrolled memory allocation.

Both vulnerabilities score 6.5 and can terminate Elasticsearch nodes. Fixes for these issues are available in versions 8.19.23, 9.4.8, and 9.5.5.

For Elastic Endpoint, CVE-2026-102413, rated 6.2, allows specially crafted filenames to trigger repeated crashes in certain Windows locales, including Chinese, Japanese, and Korean. This could degrade or turn off real-time malware prevention and behavioral detection.

Administrators should prioritize upgrades and review uploaded Fleet package histories for reused datasets and unexpected changes in ingest pipelines. Until patching is complete, restrict custom package uploads to trusted superusers.

Elastic remediated the Kibana flaw in Serverless before its disclosure. Endpoint fixes require versions 8.19.22, 9.4.8, or 9.5.5; users still on the affected 9.2.x and 9.3.x lines must migrate to a supported release line.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago