CVE-2026-102406
Kibana Fleet authz bypass enables cross-tenant data interception
Elastic ESA-2026-187 says Kibana Fleet package installation failed to verify ownership of an existing data-stream identifier, so a user with delegated Fleet custom-package privileges could redirect another tenant’s ingest path. CVSS 3.1 8.8. Fixed in 8.19.22, 9.4.7, and 9.5.4. Not in CISA KEV. No public PoC confirmed.
- CVSS
- 8.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Elastic
- Products
- Kibana
- Affected
- 8.14.0 through 8.19.21 inclusive; 9.0.0 through 9.4.6 inclusive; 9.5.0 through 9.5.3 inclusive. Affects Fleet-enabled deployments where a non-superuser can install custom uploaded integration packages (self-managed and Elastic Cloud Hosted).
- Fixed
- 8.19.22, 9.4.7, and 9.5.4 (and later releases containing the same fix), per Elastic ESA-2026-187.
- CWE
- CWE-639
- Published
- 6 Oct 2026
- Updated
- 7 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-102406 is an authorization bypass in Elastic Kibana, disclosed as ESA-2026-187. Elastic scores CVSS 3.1 8.8 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and assigns CWE-639. In Fleet’s package installation path, a user who holds delegated Fleet package-management privileges—but not direct Elasticsearch administrative privileges—could claim a data-stream identifier already used by another tenant on the same Kibana deployment. Elastic states that ownership of that identifier was not verified before Fleet applied the uploaded package’s generated index and ingest-pipeline settings to already-existing infrastructure. An attacker could therefore redirect another tenant’s subsequent ingest through infrastructure under their control, exposing that data to unauthorized disclosure and modification and preventing it from reaching its intended destination. Elastic notes that interception can continue after the malicious package is removed until the affected infrastructure is remediated separately. Here “tenant” means a user or team sharing one Kibana deployment, not a separate Elastic Cloud organization.
Affected ranges are Kibana 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3 when Fleet custom-package install privileges are granted to non-superusers. Fixed releases are 8.19.22, 9.4.7, and 9.5.4. NVD published the record on 6 October 2026. GitHub advisory GHSA-gpr2-2mpc-hvf2 mirrors the vendor score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none. No public proof-of-concept repository was confirmed for this CVE at drafting time.