Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-103007

Elasticsearch manage_roles scope bypass enables privilege escalation

Elastic ESA-2026-197 says Elasticsearch incorrect authorization in the non-default manage_roles delegated privilege can let a holder with broad index patterns expand access to restricted indices, including internal security data, up to full cluster admin. CVSS 3.1 7.2. Fixed in 8.19.22, 9.4.7, and 9.5.4. Not in CISA KEV. No public PoC confirmed.

CVSS
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Elastic
Products
Elasticsearch
Affected
8.16.0 through 8.19.21 inclusive; 9.0.0 through 9.4.6 inclusive; 9.5.0 through 9.5.3 inclusive. Only when the delegated manage_roles privilege uses wildcard or regular-expression index patterns that can match restricted or system indices. Not available on Elastic Cloud Serverless.
Fixed
8.19.22, 9.4.7, and 9.5.4 (and later releases verified to contain the fix), per Elastic ESA-2026-197.
Published
6 Oct 2026
Updated
7 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-103007 is an incorrect-authorization weakness in Elastic Elasticsearch, disclosed as ESA-2026-197. Elastic scores CVSS 3.1 7.2 with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H and assigns CWE-863. A configurable, non-default privilege lets an administrator delegate limited role-management capability (manage_roles) to another user, scoped to specific indices. Elastic states that the authorization check enforcing that scope does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly scoped index pattern can update their own assigned role to reach indices that should remain restricted, including internal security data, and Elastic says this can enable further escalation up to full administrative control of the cluster.

Affected ranges are Elasticsearch 8.16.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3, and only when manage_roles index names include wildcards or regular expressions that can match restricted or system indices. Deployments that do not use the feature, or that scope it to literal index names only, are outside the affected configuration. Elastic says the feature is not available on Elastic Cloud Serverless. Fixed releases are 8.19.22, 9.4.7, and 9.5.4. NVD published the record on 6 October 2026. GitHub advisory GHSA-5jrv-cmh5-3vmg mirrors the vendor score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none. No public proof-of-concept repository was confirmed for this CVE at drafting time.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-103007