CVE-2026-103007

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-07: 210-07
Referenced assets2 URLs
Full discourse2 posts
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: Elastic patches two high-severity authorization flaws in the Elastic Stack (ESA-2026-187 and ESA-2026-197). 🔸 CVE-2026-102406 (Kibana, CVSS 8.8): Fleet custom-package install does not verify ownership of an existing data-stream ID, so an authenticated non-superuser can intercept or modify another tenant's data. 🔸 CVE-2026-103007 (Elasticsearch, CVSS 7.2): the manage_roles scope check misses a role setting that expands index matching, which can escalate to restricted or system indices and full cluster administration when wildcard or regex role patterns are in use. ⚠️ Affected ranges include Kibana 8.14.0–8.19.21 / 9.0.0–9.4.6 / 9.5.0–9.5.3 and Elasticsearch 8.16.0–8.19.21 / 9.0.0–9.4.6 / 9.5.0–9.5.3 (with the conditions above). Not in CISA KEV, and no public PoC confirmed. 🔴 Upgrade to Elastic Stack 8.19.22, 9.4.7, or 9.5.4. Full breakdown 👉 https://www.threatwire.tech/news/elastic-stack-security-update-cve-2026-102406-and-cve-2026-103007 #CyberSecurity #InfoSec #Elastic #Kibana #Elasticsearch

    020141571
    1.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Elastic fixes 14 Elastic Stack vulnerabilities, including Kibana flaw CVE-2026-102406 and Elasticsearch bug CVE-2026-103007. Upgrade now. #Elastic #Elasticsearch #Kibana #ElasticDefend #CVE2026102406 #CVE2026103007 #DataSecurity #Vulnerability https://securityonline.info/elastic-stack-vulnerabilities/

    00000271
    13.0K followersView on X

Explore more