Index
Search
Search the public record. Drafts and scheduled notes are not included.
High
news
Elastic Stack security update covers CVE-2026-102406 and CVE-2026-103007
Elastic published ESA-2026-187 for Kibana (CVE-2026-102406, CVSS 8.8 Fleet cross-tenant intercept) and ESA-2026-197 for Elasticsearch (CVE-2026-103007, CVSS 7.2 manage_roles escalation). Fixed in 8.19.22, 9.4.7, and 9.5.4. Not in CISA KEV. No public PoC confirmed.
Published 3h ago
HighNo PoC
CVE-2026-102406
Kibana Fleet authz bypass enables cross-tenant data interception
Auth bypass
Published 12h ago
HighNo PoC
CVE-2026-103007
Elasticsearch manage_roles scope bypass enables privilege escalation
Auth bypass
Published 12h ago