CVE-2026-102406

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, to claim a data stream identifier already in use by another tenant. Because ownership of that identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, an attacker could redirect an existing tenant's data stream through infrastructure under their control. This exposed the affected tenant's subsequently ingested data to unauthorized disclosure and modification, and prevented that data from reaching its intended destination. Interception could continue even after the malicious package was removed, requiring separate remediation of the affected infrastructure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-07: 310-07
Referenced assets2 URLs
Full discourse3 posts
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: Elastic patches two high-severity authorization flaws in the Elastic Stack (ESA-2026-187 and ESA-2026-197). 🔸 CVE-2026-102406 (Kibana, CVSS 8.8): Fleet custom-package install does not verify ownership of an existing data-stream ID, so an authenticated non-superuser can intercept or modify another tenant's data. 🔸 CVE-2026-103007 (Elasticsearch, CVSS 7.2): the manage_roles scope check misses a role setting that expands index matching, which can escalate to restricted or system indices and full cluster administration when wildcard or regex role patterns are in use. ⚠️ Affected ranges include Kibana 8.14.0–8.19.21 / 9.0.0–9.4.6 / 9.5.0–9.5.3 and Elasticsearch 8.16.0–8.19.21 / 9.0.0–9.4.6 / 9.5.0–9.5.3 (with the conditions above). Not in CISA KEV, and no public PoC confirmed. 🔴 Upgrade to Elastic Stack 8.19.22, 9.4.7, or 9.5.4. Full breakdown 👉 https://www.threatwire.tech/news/elastic-stack-security-update-cve-2026-102406-and-cve-2026-103007 #CyberSecurity #InfoSec #Elastic #Kibana #Elasticsearch

    020141571
    1.7K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - Kibana Fleet Package Install AuthZ Bypass via Data Stream ID Claim (CVE-2026-102406) Kibana Fleet package installation lets a user with delegated package-management privileges claim a data stream identifier already used by another tenant. Ownership of the identifier isn’t validated before applying index + ingest pipeline settings, enabling redirection of another tenant’s data stream through attacker-controlled infra for cross-tenant data interception/modification with persistence. 👉Affected: Kibana 8.14.0–8.19.21, 9.0.0-9.4.6, 9.5.0–9.5.3 Fixed in: 8.19.22, 9.4.7, 9.5.4 and later.

    0001041
    311 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Elastic fixes 14 Elastic Stack vulnerabilities, including Kibana flaw CVE-2026-102406 and Elasticsearch bug CVE-2026-103007. Upgrade now. #Elastic #Elasticsearch #Kibana #ElasticDefend #CVE2026102406 #CVE2026103007 #DataSecurity #Vulnerability https://securityonline.info/elastic-stack-vulnerabilities/

    00000271
    13.0K followersView on X

Explore more