Threat reportVulnerabilityTL-2026-3268
Elastic Patches 14 Security Flaws Including Kibana Cross-Tenant Data Interception (CVE-2026-102406)
Elastic Patches 14 Security Flaws Including Kibana (TL-2026-3268), also tracked as ESA-2026-185, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-10. It has no confirmed attribution, affects Elastic Kibana, references 14 CVEs (CVE-2026-102406, CVE-2026-103009, CVE-2026-103008), maps to 7 MITRE ATT&CK techniques (T1078, T1190, T1213), and is covered by 9 detection rules and 5 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 14Referenced vulnerabilities
- Techniques
- 7MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 5Indicators of compromise
Key facts for TL-2026-3268
- Threat ID
- TL-2026-3268
- Also known as
- ESA-2026-185, ESA-2026-187, ESA-2026-194, ESA-2026-198, ESA-2026-199
- Severity
- HIGH
- CVSS
- 8.8
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise, managed-security-services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 5
How Elastic Patches 14 Security Flaws Including Kibana works
On 2026-10-06 Elastic published 14 security advisories (10 Elasticsearch, 3 Kibana, 1 Elastic Agent/Endpoint). The highest-rated, CVE-2026-102406 (CVSS 8.8), is a Kibana Fleet authorization bypass that lets a user with delegated package-management privileges redirect another tenant's data stream through attacker-controlled infrastructure. No active exploitation, public PoC, or attribution has been reported.
Elastic disclosed 14 advisories (ESA-2026-185 through ESA-2026-199) on 2026-10-06 affecting Elasticsearch, Kibana and Elastic Agent/Endpoint. All are fixed in current releases; none is reported as exploited in the wild, and none is listed in CISA KEV at the time of writing.
CVE-2026-102406 (ESA-2026-187, Kibana, CVSS 8.8, CWE-639 Authorization Bypass Through User-Controlled Key) is the most severe. During Fleet package installation, a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, could claim a data stream identifier already in use by another tenant (a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization). Because ownership of the identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, the attacker could redirect the victim's data stream through infrastructure under their control. The tenant's subsequently ingested data is exposed to unauthorized disclosure and modification and may not reach its intended destination. Interception can continue after the malicious package is removed, so the affected infrastructure requires separate remediation. Affected: Kibana 8.14.0-8.19.21, 9.0.0-9.4.6 and 9.5.0-9.5.3; fixed in 8.19.22, 9.4.7 and 9.5.4. Elastic Cloud Serverless was patched before public disclosure. Elastic's interim guidance is to restrict custom package uploads to superusers, audit installation history for unexpected package claims on existing datasets, and check for unexpected ingest pipeline modifications on data streams.
CVE-2026-103009 (ESA-2026-199, Elasticsearch, CVSS 7.1) stems from inconsistent shard identification in cross-cluster requests. It requires exposure of Remote Cluster Security 2.0 and cannot be exploited through the REST API; an API key authorized for one index could read documents, mappings and metadata of another index. CVE-2026-103007 (ESA-2026-197, CVSS 7.2) and CVE-2026-102407 (ESA-2026-188, CVSS 5.4) are privilege-escalation issues in Elasticsearch.
Several Elasticsearch flaws are authenticated denial-of-service conditions. CVE-2026-102404 (ESA-2026-185, CVSS 6.5, CWE-400, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) lets a low-privileged user submit crafted ES|QL queries that cause uncontrolled memory growth and node termination, repeatable and including via queries embedded in shared resources. CVE-2026-103008 (ESA-2026-198, CVSS 6.5) uses deeply nested scripted geometry in runtime-field processing to exhaust stack space and stop nodes. Further DoS issues: CVE-2026-102408, CVE-2026-102409, CVE-2026-102411, CVE-2026-103005, CVE-2026-103006. Two further Kibana issues (CVE-2026-102410, CVE-2026-102412) are information disclosure flaws rated 4.3 and 6.5.
CVE-2026-102413 (ESA-2026-194, Elastic Agent/Endpoint, CVSS 6.2, CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, CWE-248 Uncaught Exception) lets a specially crafted file name crash the Elastic Endpoint process on Windows hosts using Chinese, Japanese or Korean locales. The process crashes and restarts repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection while the condition persists. Affected: 8.19.13-8.19.21, 9.2.7-9.2.8, 9.3.0-9.3.8, 9.4.0-9.4.7, 9.5.0-9.5.4; fixed in 8.19.22, 9.4.8, 9.5.5. No fix exists for 9.2.x or 9.3.x, and no workaround is available.
The sources do not state exploit mechanics beyond the above, publish no network IOCs, and name no threat actor. Per-advisory version ranges for the less-prominent advisories were taken from a secondary summary and should be confirmed against the individual ESA posts.
MITRE ATT&CK techniques used in TL-2026-3268
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
Impact
T1499.004 Application or System Exploitation; T1565.001 Stored Data Manipulation; T1565.002 Transmitted Data Manipulation
defense-impairment
Affected products and versions in Elastic Patches 14 Security Flaws Including Kibana
- Elastic — Kibana
Vulnerable versions: 8.14.0-8.19.21; 9.0.0-9.4.6; 9.5.0-9.5.3
Fixed in: 8.19.22; 9.4.7; 9.5.4 - Elastic — Elasticsearch
Vulnerable versions: 8.x through 8.19.22; 9.0 through 9.5.4 (varies by advisory)
Fixed in: 8.19.23; 9.4.8; 9.5.5 - Elastic — Elastic Agent / Endpoint (Elastic Defend)
Vulnerable versions: 8.19.13-8.19.21; 9.2.7-9.2.8; 9.3.0-9.3.8; 9.4.0-9.4.7; 9.5.0-9.5.4
Fixed in: 8.19.22; 9.4.8; 9.5.5
Remediation for Elastic Patches 14 Security Flaws Including Kibana
Patches
- Kibana 8.19.22, 9.4.7, 9.5.4 (CVE-2026-102406)
- Elasticsearch 8.19.23, 9.4.8, 9.5.5 (CVE-2026-103009, CVE-2026-103008, CVE-2026-102404)
- Elastic Agent / Endpoint 8.19.22, 9.4.8, 9.5.5 (CVE-2026-102413)
Immediate actions
- Upgrade Kibana to 8.19.22, 9.4.7 or 9.5.4 or later
- Restrict custom Fleet package uploads to trusted superusers until patched
- Audit Fleet package installation history for unexpected package claims on existing datasets
- Check data streams for unexpected ingest pipeline modifications and verify data stream ownership
Workarounds
- CVE-2026-102406: restrict custom package upload permissions to superusers
- CVE-2026-102413: no workaround; upgrade required
Longer-term hardening
- Limit delegated Fleet package-management privileges to the minimum set of users
- Monitor Elastic Endpoint health for repeated crash/restart on CJK-locale Windows hosts
- Move off unsupported 9.2.x and 9.3.x release lines
CVEs associated with Elastic Patches 14 Security Flaws Including Kibana
Weaknesses (CWE) in Elastic Patches 14 Security Flaws Including Kibana
Timeline of Elastic Patches 14 Security Flaws Including Kibana
- CVE-2026-102406 and related CVE records published with CWE-639 classification for the Kibana flaw.
- Elastic Agent/Endpoint 8.19.22, 9.4.8 and 9.5.5 released, fixing CVE-2026-102413 (ESA-2026-194); no fix for 9.2.x and 9.3.x lines.
- Elasticsearch 8.19.23, 9.4.8 and 9.5.5 released, fixing CVE-2026-103009 (CVSS 7.1), CVE-2026-103008 and CVE-2026-102404 (CVSS 6.5 each).
- Kibana 8.19.22, 9.4.7 and 9.5.4 released, fixing CVE-2026-102406 (ESA-2026-187, CVSS 8.8); Elastic Cloud Serverless was patched before public disclosure.
- Elastic publishes 14 security advisories (ESA-2026-185 to ESA-2026-199) covering Elasticsearch, Kibana and Elastic Agent/Endpoint.
- GBHackers reports the 14 advisories; no active exploitation, PoC, IOCs or attribution stated.
Sources cited for Elastic Patches 14 Security Flaws Including Kibana
- Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
- Elastic Security Announcements
- Kibana 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-187)
- Elastic Agent / Endpoint 8.19.22, 9.4.8, and 9.5.5 Security Update (ESA-2026-194)
- CVE-2026-102406 - OpenCVE
- CVE-2026-102413 - OpenCVE
- CVE-2026-102404 - The Hacker Wire
- Elastic disclosed 14 security advisories affecting Elasticsearch, Kibana, Elastic Agent / Endpoint
Detection coverage for TL-2026-3268
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3268 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.