ELASTIC has issued 14 security advisories covering Elasticsearch, Kibana and Elastic Defend, with three rated High and a maximum CVSSv3 score of 8.8 for a Kibana Fleet flaw. The advisories warn of privilege escalation, cross‑cluster data exposure, data hijack in Fleet, and several denial‑of‑service vectors. While the disclosures note that exploitation status is unknown, there is no confirmed in‑the‑wild exploitation at the time of reporting. Administrators are urged to apply the latest fixed releases across the Elastic Stack.
Notable flaws include CVE-2026-102406 in Kibana Fleet, which could allow a user with delegated package rights to hijack an existing data stream and potentially intercept data even after the malicious package is removed. CVE-2026-103007 (privilege escalation) affects a non-default delegated role‑management privilege, enabling a user to modify their own role to access restricted indices and potentially reach administrative control.
CVE-2026-103009 (cross‑cluster data exposure) impacts cross‑cluster search where two separate shard attributes enable a user to read indices they should not reach. The batch also includes several denial‑of‑service conditions, including a data‑stream bug and a Defender crash on certain Windows locales, with some issues requiring manual recovery. Affected versions span Elasticsearch 8.x up to 8.19.22, 9.4.7 and 9.5.4, and Kibana 8.14.0 through 9.5.3, depending on the issue.
Patches comparable across the boards are Elasticsearch 8.19.23, 9.4.8 or 9.5.5 with matching Kibana and Elastic Agent updates; organisations should review Fleet rights and delegated role privileges as part of the immediate remediation.