Elastic publishes 14 security advisories for Elasticsearch, Kibana and Elastic Agent/Endpoint; worst is a Kibana Fleet flaw that lets delegated package installers intercept other teams' data (CVE-2026-102406, CVSS 8.8)
Elastic posted 14 advisories (ESA-2026-185 and ESA-2026-187 to 199) on 6 October 2026. The highest-rated, ESA-2026-187 / CVE-2026-102406 (CVSS 3.1 8.8), is in Kibana's Fleet package installation: a user who has been given Fleet privileges to install custom (uploaded) integration packages, but no direct Elasticsearch admin rights, can claim a data stream identifier already used by another user or team in the same Kibana deployment. Fleet then applies the attacker's index and ingest-pipeline settings, so newly ingested data flows through infrastructure the attacker controls and stops reaching its intended destination. Elastic warns the interception can continue after the malicious package is removed, so affected infrastructure must be checked and repaired separately. It affects Kibana 8.14.0 to 8.19.21, 9.0.0 to 9.4.6 and 9.5.0 to 9.5.3, self-managed and Elastic Cloud Hosted, where delegated users can upload custom packages. Other notable fixes: ESA-2026-199 / CVE-2026-103009 (7.1), a cross-cluster search authorisation bypass that only affects clusters acting as a fulfilling cluster under Remote Cluster Security 2.0; ESA-2026-197 / CVE-2026-103007 (7.2), privilege escalation through the delegated manage_roles privilege when it uses wildcard or regex index patterns; and ESA-2026-193 / CVE-2026-102412 (6.5), where limited Fleet users could read Fleet Server host TLS private keys (Kibana 9.3 to 9.5). The rest are mostly authenticated denial-of-service bugs in Elasticsearch, plus an Elastic Endpoint crash loop on Windows hosts with Chinese, Japanese or Korean locales that can switch off Elastic Defend protection. Elastic does not report exploitation. Primary: Elastic security announcements.
- Product
- Elastic Kibana (Fleet), Elasticsearch, Elastic Agent / Elastic Endpoint (Elastic Defend)
- Versions
- Kibana 8.14.0–8.19.21, 9.0.0–9.4.6, 9.5.0–9.5.3 (CVE-2026-102406); Elasticsearch 8.13.0–8.19.22, 9.0.0–9.4.7, 9.5.0–9.5.4 (CVE-2026-103009); other advisories vary; no fixes for the unmaintained 9.2 and 9.3 lines
- CVSS
- 8.8
- Exploited in Australia?
- unknown
- Patch to
- Kibana 8.19.22, 9.4.7 or 9.5.4 for CVE-2026-102406; for the full set move to Elasticsearch, Kibana and Elastic Agent 8.19.23, 9.4.8 or 9.5.5. Until then, remove custom-package upload rights from non-superuser Fleet users, audit data streams and ingest pipelines for settings you did not create, and leave 9.2/9.3.
Primary: Elastic — Kibana 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-187) (6 Oct 2026) · Vendor: Elastic — Security announcements (ESA-2026-185, 187 to 199, 6 Oct 2026) · CVE: CVE-2026-102406, CVE-2026-103009, CVE-2026-103007, CVE-2026-102412 · Cybersecurity News — Elastic fixes 14 security flaws (8 Oct 2026)
