Skip to content
TrustList
News

Elastic patches 14 flaws across Elasticsearch, Kibana and Endpoint

Editorial

By TrustList Editorial

Three are rated High, led by a Kibana Fleet flaw scoring 8.8 that lets a delegated user redirect another team data stream. Several older release lines get no fix at all.

About Elastic patches 14 flaws across Elasticsearch, Kibana and Endpoint

Elastic patches 14 flaws across Elasticsearch, Kibana and Endpoint

6 October 2026: Elastic published 14 security advisories in one batch, covering Elasticsearch, Kibana and the Elastic Defend endpoint agent. Three are rated High, 11 Medium, and the company lists no known exploitation or indicators of compromise for any of them. Elasticsearch 8.19.23, 9.4.8 and 9.5.5 carry the Elasticsearch fixes.

Not yet independently verified. Single source: Elastic's own security announcements forum. No exploitation is reported in the advisories we read. We will update this when it can be confirmed, and remove this note.

The most serious is ESA-2026-187 (CVE-2026-102406, CVSS 8.8), a Kibana flaw in Fleet package installation. A user with delegated Fleet package-management privileges, but no Elasticsearch administrator rights, could claim a data stream identifier already used by another team and send that team's later data through infrastructure the attacker controls. Interception could continue after the malicious package was removed. It affects Kibana 8.14.0 to 8.19.21, 9.0.0 to 9.4.6 and 9.5.0 to 9.5.3, and is fixed in 8.19.22, 9.4.7 and 9.5.4.

Two further High-rated Elasticsearch flaws are worth checking:

  • ESA-2026-197 (CVSS 7.2): a user holding the non-default manage_roles privilege, scoped to index patterns such as * or /.*/, can edit their own role to reach internal security indices and escalate to full cluster control. Elastic's workaround is to restrict such grants to literal index names.
  • ESA-2026-199 (CVSS 7.1): cross-cluster search using Remote Cluster Security 2.0 can be tricked into reading an index the API key was not authorised for. Only fulfilling clusters are affected, and disabling remote cluster connections removes the exposure.

Eight of the 14 are denial-of-service bugs that let a low-privileged authenticated user crash or starve a node, through deeply nested aggregations, scripted geometry fields, ES|QL queries or oversized connector descriptions. The rest are authorisation and information-disclosure issues in Kibana and Elasticsearch.

Elastic says Cloud Serverless was patched before disclosure in all but the endpoint case, which is a host-side agent.

Teams on older lines have the harder choice. For several advisories Elastic states that no fix exists for 9.1.x, 9.2.x, 9.3.x or 7.17.x, and tells those users to move to a supported release line.

Company profile on TrustList: Elastic

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy