
🚨 SECURITY UPDATE: Elastic patches two high-severity authorization flaws in the Elastic Stack (ESA-2026-187 and ESA-2026-197). 🔸 CVE-2026-102406 (Kibana, CVSS 8.8): Fleet custom-package install does not verify ownership of an existing data-stream ID, so an authenticated non-superuser can intercept or modify another tenant's data. 🔸 CVE-2026-103007 (Elasticsearch, CVSS 7.2): the manage_roles scope check misses a role setting that expands index matching, which can escalate to restricted or system indices and full cluster administration when wildcard or regex role patterns are in use. ⚠️ Affected ranges include Kibana 8.14.0–8.19.21 / 9.0.0–9.4.6 / 9.5.0–9.5.3 and Elasticsearch 8.16.0–8.19.21 / 9.0.0–9.4.6 / 9.5.0–9.5.3 (with the conditions above). Not in CISA KEV, and no public PoC confirmed. 🔴 Upgrade to Elastic Stack 8.19.22, 9.4.7, or 9.5.4. Full breakdown 👉 https://www.threatwire.tech/news/elastic-stack-security-update-cve-2026-102406-and-cve-2026-103007 #CyberSecurity #InfoSec #Elastic #Kibana #Elasticsearch


