VYPR
patchPublished Oct 8, 2026· 1 source

Elastic Patches 14 Vulnerabilities, Including Critical Kibana Data Interception Flaw

Elastic has released security updates addressing 14 vulnerabilities across its Elasticsearch, Kibana, and Elastic Agent/Endpoint products, with a critical Kibana flaw allowing data interception.

Elastic has issued a significant security update, patching a total of 14 vulnerabilities affecting its core products: Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among the fixes is a critical flaw in Kibana that could allow delegated users to intercept sensitive data belonging to other tenants.

The most severe vulnerability, tracked as CVE-2026-102406 and rated with a CVSS score of 8.8, resides within Kibana's Fleet package installation process. This flaw enables an attacker with the ability to install custom Fleet packages to hijack data streams belonging to other tenants. By exploiting this, an attacker could redirect data ingestion pipelines to their own infrastructure, allowing them to intercept, view, and potentially modify data before it reaches its intended destination. Elastic has warned that the interception can persist even after the malicious package is removed, necessitating manual inspection and repair of affected infrastructure.

This vulnerability impacts Kibana versions 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3. Patches are available in versions 8.19.22, 9.4.7, and 9.5.4. Both self-managed and Elastic Cloud hosted environments are vulnerable if delegated users have the ability to upload custom integration packages.

Beyond the critical Kibana flaw, Elastic has also addressed other high-severity issues. CVE-2026-103009 (CVSS 7.1) allows for authorization bypass in cross-cluster search operations using Remote Cluster Security 2.0, potentially exposing sensitive documents and metadata. This vulnerability requires access to the remote cluster transport interface and cannot be exploited via the REST API.

Denial-of-service (DoS) vulnerabilities have also been remediated in Elasticsearch. CVE-2026-103008 (CVSS 6.5) allows an authenticated user to cause excessive recursion through scripted geometry, leading to node termination. Similarly, CVE-2026-102404 (CVSS 6.5) permits crafted ES|QL queries to exhaust system memory, disrupting cluster availability. Both issues are fixed in versions 8.19.23, 9.4.8, and 9.5.5.

Additionally, a vulnerability in Elastic Endpoint, CVE-2026-102413 (CVSS 6.2), could cause repeated crashes when processing specially crafted filenames on Windows systems with certain locales (Chinese, Japanese, Korean). These crashes could weaken or disable malware prevention and behavioral detection capabilities.

Elastic recommends administrators promptly install the applicable fixed releases and review the upgrade notes. As a temporary mitigation for the Kibana data interception flaw, Elastic advises restricting custom package uploads to superusers only until systems are fully patched. Investigators are also encouraged to scrutinize uploaded Fleet packages for any signs of reused datasets or unexpected modifications to existing ingest pipelines.

Elastic has already remediated the critical Kibana vulnerability in its Cloud Serverless offerings prior to this public disclosure, underscoring their commitment to securing their cloud-based services.

Synthesized by Vypr AI