VYPR
Vypr IntelligenceAI-generatedSep 26, 2026· 11 CVEs

Elasticsearch & Kibana: Eleven Vulnerabilities Including DoS and Privilege Escalation Disclosed Together

Elasticsearch and Kibana face eleven vulnerabilities, including DoS, privilege escalation, and authorization bypass, disclosed simultaneously on September 26, 2026.

Key findings

  • Eleven vulnerabilities disclosed together for Elastic's Elasticsearch and Kibana on September 26, 2026.
  • Multiple Uncontrolled Resource Consumption flaws leading to denial of service across both products.
  • High severity 'Confused Deputy' vulnerability (CVE-2026-72668) enables privilege escalation in Kibana Agent Builder.
  • Missing Authorization and Authorization Bypass flaws in Kibana allow unauthorized data deletion and access.
  • Users are urged to update to patched versions to mitigate risks.

On September 26, 2026, a batch of eleven vulnerabilities was disclosed for Elastic's Elasticsearch and Kibana products. The vulnerabilities, all disclosed on the same day, primarily revolve around uncontrolled resource consumption leading to denial of service, with a few critical flaws including privilege escalation and authorization bypass. These disclosures impact users of Elastic's widely-used search and analytics platform.

A significant portion of the disclosed vulnerabilities, specifically CVE-2026-94408, CVE-2026-94400, CVE-2026-94399, CVE-2026-94398, CVE-2026-94397, CVE-2026-94396, CVE-2026-82300, and CVE-2026-82294, are categorized under Uncontrolled Resource Consumption (CWE-400). These flaws can lead to denial of service through excessive allocation (CAPEC-130) in both Elasticsearch and Kibana. While most of these are rated as Medium severity, their sheer number indicates a potential for widespread disruption if exploited.

Further compounding the risk, three other vulnerabilities present more direct threats to data integrity and system access. CVE-2026-78582, a Missing Authorization vulnerability in Kibana, allows an authenticated user with specific privileges to delete shared Synthetics monitors. CVE-2026-72662, an Authorization Bypass vulnerability in Kibana, enables authenticated users to enumerate, read, modify, and delete data by exploiting functionality not properly constrained by Access Control Lists (ACLs).

The most severe of the batch is CVE-2026-72668, a High severity 'Confused Deputy' vulnerability (CWE-441) in the Kibana Agent Builder. This flaw allows a non-administrative user to escalate privileges by tricking a higher-privileged user into performing actions under their identity. This could lead to unauthorized administrative access and control over the Elastic environment. Vypr Intelligence

The disclosures highlight a critical need for users to update their Elastic installations promptly. While specific patch versions were not detailed in the initial disclosures, the coordinated release suggests that updates addressing these issues are available. Users are strongly advised to consult Elastic's official security advisories for detailed information on affected versions and the recommended patching procedures.

The simultaneous disclosure of these eleven vulnerabilities underscores the importance of timely patching and security vigilance for users of the Elastic stack. The range of issues, from denial-of-service vectors to privilege escalation, necessitates a comprehensive review of security configurations and an immediate application of available updates to mitigate potential risks.

The batch of vulnerabilities includes:

Users are urged to apply the latest security patches provided by Elastic to protect their systems from these vulnerabilities. Vypr Intelligence

AI-written article. Grounded in 11 CVE records listed below.