Elastic patches 14 flaws across Elasticsearch, Kibana and Endpoint
EditorialBy TrustList Editorial
Three are rated High, led by a Kibana Fleet flaw scoring 8.8 that lets a delegated user redirect another team data stream. Several older release lines get no fix at all.
- Enterprise Search Software
- Log Management
- Cybersecurity
- Vulnerability Management
About Elastic patches 14 flaws across Elasticsearch, Kibana and Endpoint
Elastic patches 14 flaws across Elasticsearch, Kibana and Endpoint
6 October 2026: Elastic published 14 security advisories in one batch, covering Elasticsearch, Kibana and the Elastic Defend endpoint agent. Three are rated High, 11 Medium, and the company lists no known exploitation or indicators of compromise for any of them. Elasticsearch 8.19.23, 9.4.8 and 9.5.5 carry the Elasticsearch fixes.
Not yet independently verified. Single source: Elastic's own security announcements forum. No exploitation is reported in the advisories we read. We will update this when it can be confirmed, and remove this note.
The most serious is ESA-2026-187 (CVE-2026-102406, CVSS 8.8), a Kibana flaw in Fleet package installation. A user with delegated Fleet package-management privileges, but no Elasticsearch administrator rights, could claim a data stream identifier already used by another team and send that team's later data through infrastructure the attacker controls. Interception could continue after the malicious package was removed. It affects Kibana 8.14.0 to 8.19.21, 9.0.0 to 9.4.6 and 9.5.0 to 9.5.3, and is fixed in 8.19.22, 9.4.7 and 9.5.4.
Two further High-rated Elasticsearch flaws are worth checking:
- ESA-2026-197 (CVSS 7.2): a user holding the non-default manage_roles privilege, scoped to index patterns such as * or /.*/, can edit their own role to reach internal security indices and escalate to full cluster control. Elastic's workaround is to restrict such grants to literal index names.
- ESA-2026-199 (CVSS 7.1): cross-cluster search using Remote Cluster Security 2.0 can be tricked into reading an index the API key was not authorised for. Only fulfilling clusters are affected, and disabling remote cluster connections removes the exposure.
Eight of the 14 are denial-of-service bugs that let a low-privileged authenticated user crash or starve a node, through deeply nested aggregations, scripted geometry fields, ES|QL queries or oversized connector descriptions. The rest are authorisation and information-disclosure issues in Kibana and Elasticsearch.
Elastic says Cloud Serverless was patched before disclosure in all but the endpoint case, which is a host-side agent.
Teams on older lines have the harder choice. For several advisories Elastic states that no fix exists for 9.1.x, 9.2.x, 9.3.x or 7.17.x, and tells those users to move to a supported release line.
Company profile on TrustList: Elastic
Sources
Categories & features
- Enterprise Search Software
- Log Management
- Cybersecurity
- Vulnerability Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.