Elastic has rolled out fixes for 14 security vulnerabilities across Elasticsearch, Kibana, and Elastic Agent/Endpoint — including a serious bug in Kibana that allows delegated Fleet users to intercept data from other users or teams.
What Was the High-Severity Bug?
The most critical flaw, CVE-2026-102406 (CVSS score 8.8), impacts Fleet’s package installation process in Kibana. It fails to verify ownership before applying integration settings to an existing data stream. This means a malicious delegated user could claim a data stream already tied to another tenant and change its ingest-pipeline and index settings — diverting new data through infrastructure under their control. Attackers could then see, modify, or block data meant for someone else, even after the malicious package has been removed. Elastic recommends administrators audit and remediate infrastructure that was affected rather than relying solely on package deletion.
Other Serious Flaws & Affected Versions
Among the other vulnerabilities is CVE-2026-103009 (score 7.1), which affects cross-cluster search under Remote Cluster Security 2.0. An exploit allows requests that seem to authorize access to one index but actually pull data from a different, unauthorized index — leaking sensitive documents, mappings, or metadata. This flaw requires access via the remote cluster transport interface and can’t be triggered through the REST API.
There are also denial-of-service risks. CVE-2026-103008 empowers an authenticated user with index read access to cause excessive recursion through scripted geometry, resulting in a node crash. CVE-2026-102404 allows crafted Elasticsearch SQL (ES|QL) queries to consume memory in a way that disrupts the cluster’s availability. Both carry moderate severity (CVSS 6.5) and are fixed in recent patches.
Another vulnerability in Elastic Endpoint, CVE-2026-102413 (rating 6.2), causes crashes when handling specially crafted filenames in certain Windows locales, such as Chinese, Japanese, or Korean. These crashes could weaken or disable key protection mechanisms like malware prevention and behavioral monitoring.
What Versions Are Vulnerable & What To Do
Kibana deployments running versions 8.14.0 through 8.19.21, or 9.0.0 through 9.4.6, or 9.5.0 through 9.5.3 are exposed to these issues. The fixes have been included in Kibana versions 8.19.22, 9.4.7, and 9.5.4. Elasticsearch patches for related flaws are in versions 8.19.23, 9.4.8, and 9.5.5. Elastic Cloud Hosted and self-managed installations are both affected when users are allowed to upload custom integration packages without superuser privileges.
Until patched, Elastic advises that only full superusers be allowed to upload custom Fleet packages, and admins should review uploaded packages for reused dataset identifiers and unauthorized pipeline changes. The Kibana flaw was already remediated in the Elastic Cloud Serverless environment before public disclosure.
Threat Context: These vulnerabilities expose multi-tenant Kibana deployments to severe risks, especially where delegated users have elevated permissions. The potential for data interception and tampering threatens confidentiality, integrity, and availability across teams operating in shared environments.
What this means: if you run solutions like Kibana, Fleet packages, Elasticsearch clusters, or Elastic Endpoint — patch now. Oversight of permissions for custom package uploads is critical. Moving forward, such privileges should be heavily restricted or reserved only for superusers until stricter controls are always in place. Also monitor for indicators of compromise that might persist beyond patching due to lingering misconfigurations or malicious artifacts.