# Elastic Patches 14 Security Flaws Including Kibana Cross-Tenant Data Interception (CVE-2026-102406)

> On 2026-10-06 Elastic published 14 security advisories (10 Elasticsearch, 3 Kibana, 1 Elastic Agent/Endpoint). The highest-rated, CVE-2026-102406 (CVSS 8.8), is a Kibana Fleet authorization bypass that lets a user with delegated package-management privileges redirect another tenant's data stream through attacker-controlled infrastructure. No active exploitation, public PoC, or attribution has been reported.

- **Published:** 2026-10-10T14:45:40Z
- **Last reviewed:** 2026-10-10T14:45:40Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3268
- **ID:** TL-2026-3268
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 5 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-102406, CVE-2026-103009, CVE-2026-103008, CVE-2026-102404, CVE-2026-102413, CVE-2026-102407, CVE-2026-102408, CVE-2026-102409, CVE-2026-102410, CVE-2026-102411, CVE-2026-102412, CVE-2026-103005, CVE-2026-103006, CVE-2026-103007

## Description

Elastic disclosed 14 advisories (ESA-2026-185 through ESA-2026-199) on 2026-10-06 affecting Elasticsearch, Kibana and Elastic Agent/Endpoint. All are fixed in current releases; none is reported as exploited in the wild, and none is listed in CISA KEV at the time of writing.

CVE-2026-102406 (ESA-2026-187, Kibana, CVSS 8.8, CWE-639 Authorization Bypass Through User-Controlled Key) is the most severe. During Fleet package installation, a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, could claim a data stream identifier already in use by another tenant (a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization). Because ownership of the identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, the attacker could redirect the victim's data stream through infrastructure under their control. The tenant's subsequently ingested data is exposed to unauthorized disclosure and modification and may not reach its intended destination. Interception can continue after the malicious package is removed, so the affected infrastructure requires separate remediation. Affected: Kibana 8.14.0-8.19.21, 9.0.0-9.4.6 and 9.5.0-9.5.3; fixed in 8.19.22, 9.4.7 and 9.5.4. Elastic Cloud Serverless was patched before public disclosure. Elastic's interim guidance is to restrict custom package uploads to superusers, audit installation history for unexpected package claims on existing datasets, and check for unexpected ingest pipeline modifications on data streams.

CVE-2026-103009 (ESA-2026-199, Elasticsearch, CVSS 7.1) stems from inconsistent shard identification in cross-cluster requests. It requires exposure of Remote Cluster Security 2.0 and cannot be exploited through the REST API; an API key authorized for one index could read documents, mappings and metadata of another index. CVE-2026-103007 (ESA-2026-197, CVSS 7.2) and CVE-2026-102407 (ESA-2026-188, CVSS 5.4) are privilege-escalation issues in Elasticsearch.

Several Elasticsearch flaws are authenticated denial-of-service conditions. CVE-2026-102404 (ESA-2026-185, CVSS 6.5, CWE-400, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) lets a low-privileged user submit crafted ES|QL queries that cause uncontrolled memory growth and node termination, repeatable and including via queries embedded in shared resources. CVE-2026-103008 (ESA-2026-198, CVSS 6.5) uses deeply nested scripted geometry in runtime-field processing to exhaust stack space and stop nodes. Further DoS issues: CVE-2026-102408, CVE-2026-102409, CVE-2026-102411, CVE-2026-103005, CVE-2026-103006. Two further Kibana issues (CVE-2026-102410, CVE-2026-102412) are information disclosure flaws rated 4.3 and 6.5.

CVE-2026-102413 (ESA-2026-194, Elastic Agent/Endpoint, CVSS 6.2, CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, CWE-248 Uncaught Exception) lets a specially crafted file name crash the Elastic Endpoint process on Windows hosts using Chinese, Japanese or Korean locales. The process crashes and restarts repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection while the condition persists. Affected: 8.19.13-8.19.21, 9.2.7-9.2.8, 9.3.0-9.3.8, 9.4.0-9.4.7, 9.5.0-9.5.4; fixed in 8.19.22, 9.4.8, 9.5.5. No fix exists for 9.2.x or 9.3.x, and no workaround is available.

The sources do not state exploit mechanics beyond the above, publish no network IOCs, and name no threat actor. Per-advisory version ranges for the less-prominent advisories were taken from a secondary summary and should be confirmed against the individual ESA posts.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1190 Exploit Public-Facing Application
- T1213 Data from Information Repositories
- T1685 Disable or Modify Tools
- T1565.001 Stored Data Manipulation
- T1565.002 Transmitted Data Manipulation
- T1499.004 Application or System Exploitation

## Sources

- [Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception](https://gbhackers.com/elastic-patches-14-security-flaws/)
- [Elastic Security Announcements](https://discuss.elastic.co/c/announcements/security-announcements/31)
- [Kibana 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-187)](https://discuss.elastic.co/t/390860)
- [Elastic Agent / Endpoint 8.19.22, 9.4.8, and 9.5.5 Security Update (ESA-2026-194)](https://discuss.elastic.co/t/390868)
- [CVE-2026-102406 - OpenCVE](https://app.opencve.io/cve/CVE-2026-102406)
- [CVE-2026-102413 - OpenCVE](https://app.opencve.io/cve/CVE-2026-102413)
- [CVE-2026-102404 - The Hacker Wire](https://www.thehackerwire.com/vulnerability/CVE-2026-102404/)
- [Elastic disclosed 14 security advisories affecting Elasticsearch, Kibana, Elastic Agent / Endpoint](https://rocket-boys.co.jp/?p=42818)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3268
