Threat reportVulnerabilityTL-2026-3268

Elastic Patches 14 Security Flaws Including Kibana Cross-Tenant Data Interception (CVE-2026-102406)

highPATCHED

Elastic Patches 14 Security Flaws Including Kibana (TL-2026-3268), also tracked as ESA-2026-185, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-10. It has no confirmed attribution, affects Elastic Kibana, references 14 CVEs (CVE-2026-102406, CVE-2026-103009, CVE-2026-103008), maps to 7 MITRE ATT&CK techniques (T1078, T1190, T1213), and is covered by 9 detection rules and 5 indicators of compromise.

CVSS
8.8/10High
CVEs
14Referenced vulnerabilities
Techniques
7MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
5Indicators of compromise

Key facts for TL-2026-3268

Threat ID
TL-2026-3268
Also known as
ESA-2026-185, ESA-2026-187, ESA-2026-194, ESA-2026-198, ESA-2026-199
Severity
HIGH
CVSS
8.8
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, enterprise, managed-security-services
Target regions
Global
Detection rules
9
Indicators of compromise
5

How Elastic Patches 14 Security Flaws Including Kibana works

On 2026-10-06 Elastic published 14 security advisories (10 Elasticsearch, 3 Kibana, 1 Elastic Agent/Endpoint). The highest-rated, CVE-2026-102406 (CVSS 8.8), is a Kibana Fleet authorization bypass that lets a user with delegated package-management privileges redirect another tenant's data stream through attacker-controlled infrastructure. No active exploitation, public PoC, or attribution has been reported.

Elastic disclosed 14 advisories (ESA-2026-185 through ESA-2026-199) on 2026-10-06 affecting Elasticsearch, Kibana and Elastic Agent/Endpoint. All are fixed in current releases; none is reported as exploited in the wild, and none is listed in CISA KEV at the time of writing.

CVE-2026-102406 (ESA-2026-187, Kibana, CVSS 8.8, CWE-639 Authorization Bypass Through User-Controlled Key) is the most severe. During Fleet package installation, a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, could claim a data stream identifier already in use by another tenant (a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization). Because ownership of the identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, the attacker could redirect the victim's data stream through infrastructure under their control. The tenant's subsequently ingested data is exposed to unauthorized disclosure and modification and may not reach its intended destination. Interception can continue after the malicious package is removed, so the affected infrastructure requires separate remediation. Affected: Kibana 8.14.0-8.19.21, 9.0.0-9.4.6 and 9.5.0-9.5.3; fixed in 8.19.22, 9.4.7 and 9.5.4. Elastic Cloud Serverless was patched before public disclosure. Elastic's interim guidance is to restrict custom package uploads to superusers, audit installation history for unexpected package claims on existing datasets, and check for unexpected ingest pipeline modifications on data streams.

CVE-2026-103009 (ESA-2026-199, Elasticsearch, CVSS 7.1) stems from inconsistent shard identification in cross-cluster requests. It requires exposure of Remote Cluster Security 2.0 and cannot be exploited through the REST API; an API key authorized for one index could read documents, mappings and metadata of another index. CVE-2026-103007 (ESA-2026-197, CVSS 7.2) and CVE-2026-102407 (ESA-2026-188, CVSS 5.4) are privilege-escalation issues in Elasticsearch.

Several Elasticsearch flaws are authenticated denial-of-service conditions. CVE-2026-102404 (ESA-2026-185, CVSS 6.5, CWE-400, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) lets a low-privileged user submit crafted ES|QL queries that cause uncontrolled memory growth and node termination, repeatable and including via queries embedded in shared resources. CVE-2026-103008 (ESA-2026-198, CVSS 6.5) uses deeply nested scripted geometry in runtime-field processing to exhaust stack space and stop nodes. Further DoS issues: CVE-2026-102408, CVE-2026-102409, CVE-2026-102411, CVE-2026-103005, CVE-2026-103006. Two further Kibana issues (CVE-2026-102410, CVE-2026-102412) are information disclosure flaws rated 4.3 and 6.5.

CVE-2026-102413 (ESA-2026-194, Elastic Agent/Endpoint, CVSS 6.2, CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, CWE-248 Uncaught Exception) lets a specially crafted file name crash the Elastic Endpoint process on Windows hosts using Chinese, Japanese or Korean locales. The process crashes and restarts repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection while the condition persists. Affected: 8.19.13-8.19.21, 9.2.7-9.2.8, 9.3.0-9.3.8, 9.4.0-9.4.7, 9.5.0-9.5.4; fixed in 8.19.22, 9.4.8, 9.5.5. No fix exists for 9.2.x or 9.3.x, and no workaround is available.

The sources do not state exploit mechanics beyond the above, publish no network IOCs, and name no threat actor. Per-advisory version ranges for the less-prominent advisories were taken from a secondary summary and should be confirmed against the individual ESA posts.

MITRE ATT&CK techniques used in TL-2026-3268

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories

Impact

T1499.004 Application or System Exploitation; T1565.001 Stored Data Manipulation; T1565.002 Transmitted Data Manipulation

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Elastic Patches 14 Security Flaws Including Kibana

  • Elastic — Kibana
    Vulnerable versions: 8.14.0-8.19.21; 9.0.0-9.4.6; 9.5.0-9.5.3
    Fixed in: 8.19.22; 9.4.7; 9.5.4
  • Elastic — Elasticsearch
    Vulnerable versions: 8.x through 8.19.22; 9.0 through 9.5.4 (varies by advisory)
    Fixed in: 8.19.23; 9.4.8; 9.5.5
  • Elastic — Elastic Agent / Endpoint (Elastic Defend)
    Vulnerable versions: 8.19.13-8.19.21; 9.2.7-9.2.8; 9.3.0-9.3.8; 9.4.0-9.4.7; 9.5.0-9.5.4
    Fixed in: 8.19.22; 9.4.8; 9.5.5

Remediation for Elastic Patches 14 Security Flaws Including Kibana

Patches

  • Kibana 8.19.22, 9.4.7, 9.5.4 (CVE-2026-102406)
  • Elasticsearch 8.19.23, 9.4.8, 9.5.5 (CVE-2026-103009, CVE-2026-103008, CVE-2026-102404)
  • Elastic Agent / Endpoint 8.19.22, 9.4.8, 9.5.5 (CVE-2026-102413)

Immediate actions

  • Upgrade Kibana to 8.19.22, 9.4.7 or 9.5.4 or later
  • Restrict custom Fleet package uploads to trusted superusers until patched
  • Audit Fleet package installation history for unexpected package claims on existing datasets
  • Check data streams for unexpected ingest pipeline modifications and verify data stream ownership

Workarounds

  • CVE-2026-102406: restrict custom package upload permissions to superusers
  • CVE-2026-102413: no workaround; upgrade required

Longer-term hardening

  • Limit delegated Fleet package-management privileges to the minimum set of users
  • Monitor Elastic Endpoint health for repeated crash/restart on CJK-locale Windows hosts
  • Move off unsupported 9.2.x and 9.3.x release lines

CVEs associated with Elastic Patches 14 Security Flaws Including Kibana

Weaknesses (CWE) in Elastic Patches 14 Security Flaws Including Kibana

CWE-639, CWE-400, CWE-248

Timeline of Elastic Patches 14 Security Flaws Including Kibana

  • CVE-2026-102406 and related CVE records published with CWE-639 classification for the Kibana flaw.
  • Elastic Agent/Endpoint 8.19.22, 9.4.8 and 9.5.5 released, fixing CVE-2026-102413 (ESA-2026-194); no fix for 9.2.x and 9.3.x lines.
  • Elasticsearch 8.19.23, 9.4.8 and 9.5.5 released, fixing CVE-2026-103009 (CVSS 7.1), CVE-2026-103008 and CVE-2026-102404 (CVSS 6.5 each).
  • Kibana 8.19.22, 9.4.7 and 9.5.4 released, fixing CVE-2026-102406 (ESA-2026-187, CVSS 8.8); Elastic Cloud Serverless was patched before public disclosure.
  • Elastic publishes 14 security advisories (ESA-2026-185 to ESA-2026-199) covering Elasticsearch, Kibana and Elastic Agent/Endpoint.
  • GBHackers reports the 14 advisories; no active exploitation, PoC, IOCs or attribution stated.

Sources cited for Elastic Patches 14 Security Flaws Including Kibana

Detection coverage for TL-2026-3268

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3268 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
5 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats