Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-102406

Kibana Fleet authz bypass enables cross-tenant data interception

Elastic ESA-2026-187 says Kibana Fleet package installation failed to verify ownership of an existing data-stream identifier, so a user with delegated Fleet custom-package privileges could redirect another tenant’s ingest path. CVSS 3.1 8.8. Fixed in 8.19.22, 9.4.7, and 9.5.4. Not in CISA KEV. No public PoC confirmed.

CVSS
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Elastic
Products
Kibana
Affected
8.14.0 through 8.19.21 inclusive; 9.0.0 through 9.4.6 inclusive; 9.5.0 through 9.5.3 inclusive. Affects Fleet-enabled deployments where a non-superuser can install custom uploaded integration packages (self-managed and Elastic Cloud Hosted).
Fixed
8.19.22, 9.4.7, and 9.5.4 (and later releases containing the same fix), per Elastic ESA-2026-187.
Published
6 Oct 2026
Updated
7 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-102406 is an authorization bypass in Elastic Kibana, disclosed as ESA-2026-187. Elastic scores CVSS 3.1 8.8 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and assigns CWE-639. In Fleet’s package installation path, a user who holds delegated Fleet package-management privileges—but not direct Elasticsearch administrative privileges—could claim a data-stream identifier already used by another tenant on the same Kibana deployment. Elastic states that ownership of that identifier was not verified before Fleet applied the uploaded package’s generated index and ingest-pipeline settings to already-existing infrastructure. An attacker could therefore redirect another tenant’s subsequent ingest through infrastructure under their control, exposing that data to unauthorized disclosure and modification and preventing it from reaching its intended destination. Elastic notes that interception can continue after the malicious package is removed until the affected infrastructure is remediated separately. Here “tenant” means a user or team sharing one Kibana deployment, not a separate Elastic Cloud organization.

Affected ranges are Kibana 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3 when Fleet custom-package install privileges are granted to non-superusers. Fixed releases are 8.19.22, 9.4.7, and 9.5.4. NVD published the record on 6 October 2026. GitHub advisory GHSA-gpr2-2mpc-hvf2 mirrors the vendor score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none. No public proof-of-concept repository was confirmed for this CVE at drafting time.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-102406