Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Claude Haiku 5.5 Offers Enhanced Coding and Computer Vision
October 8, 2026
Elastic Patches Critical Data Interception Flaw in Kibana (CVE-2024-5268)
October 8, 2026
US Offers $10M Reward for APT41 Hacker Over COVID-19 Research Theft
October 8, 2026
Home/CyberSecurity News/Elastic Patches Critical Data Interception Flaw in Kibana (CVE-2024-5268)
CyberSecurity News

Elastic Patches Critical Data Interception Flaw in Kibana (CVE-2024-5268)

Key Takeaways Elastic has addressed a critical data interception vulnerability in Kibana, tracked as CVE-2026-102406, with a CVSS score of 8.8. The flaw allows delegated Fleet users to hijack data...

David kimber
David kimber
October 8, 2026 3 Min Read
2 0

Key Takeaways

  • Elastic has addressed a critical data interception vulnerability in Kibana, tracked as CVE-2026-102406, with a CVSS score of 8.8.
  • The flaw allows delegated Fleet users to hijack data streams and intercept information from other users or teams within the same Kibana deployment.
  • Affected Kibana versions range from 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3.
  • Patches are available in versions 8.19.22, 9.4.7, and 9.5.4, along with fixes for several other high and medium-severity issues across Elastic products.

Elastic has released a series of security updates, patching a total of 14 vulnerabilities across its product suite, including Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a critical flaw in Kibana (CVE-2026-102406), scoring 8.8 on the CVSS scale, stands out for its potential to allow unauthorized data interception.

Table Of Content

  • Key Takeaways
  • Kibana Flaw Enables Data Stream Hijacking
  • Affected Versions and Patches
  • Additional High-Severity Vulnerabilities Addressed
  • Elasticsearch and Elastic Endpoint Updates
  • What You Should Do

Kibana Flaw Enables Data Stream Hijacking

The high-severity Kibana vulnerability, identified as CVE-2026-102406, stems from an oversight in Fleet’s package installation process. Specifically, the system failed to adequately verify ownership before applying integration settings from uploaded packages to existing data streams. This critical weakness could be exploited by an attacker with permissions to install custom Fleet packages.

Such an attacker could claim a data stream identifier already in use by another user or team within the same Kibana deployment—referred to as a “tenant”—without needing direct administrative privileges within Elasticsearch. Once control of the data stream was usurped, Fleet would apply the attacker’s custom index and ingest-pipeline settings. This action would reroute newly ingested information through infrastructure controlled by the attacker, exposing sensitive data to unauthorized access, modification, and preventing it from reaching its legitimate destination.

Elastic emphasizes that the interception could persist even after the malicious package is removed. Therefore, administrators must go beyond simply removing the package and thoroughly inspect and repair any affected infrastructure to ensure complete remediation.

Affected Versions and Patches

The critical Kibana flaw impacts versions 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3. Both self-managed and Elastic Cloud Hosted installations are vulnerable if delegated users have the ability to upload custom integration packages. Corrective patches have been released in versions 8.19.22, 9.4.7, and 9.5.4.

Additional High-Severity Vulnerabilities Addressed

Beyond the Kibana data interception flaw, Elastic also patched CVE-2026-103009, another high-severity vulnerability with a CVSS score of 7.1. This issue affects cross-cluster search when utilizing Remote Cluster Security 2.0. A specially crafted request could bypass authorization for an allowed index, granting access to a different, unauthorized index, thereby exposing documents, mappings, and metadata. This particular vulnerability requires access via the remote cluster transport interface and cannot be exploited through the REST API.

Elasticsearch and Elastic Endpoint Updates

Elasticsearch received fixes for two denial-of-service (DoS) vulnerabilities. CVE-2026-103008, with a CVSS score of 6.5, allows an authenticated user with index read access to trigger excessive recursion through scripted geometry, leading to node termination. Similarly, CVE-2026-102404, also scoring 6.5, could be exploited using crafted ES|QL queries to exhaust memory, causing repeated disruptions to cluster availability. Both Elasticsearch DoS issues are resolved in versions 8.19.23, 9.4.8, and 9.5.5.

Elastic Endpoint also received an update for CVE-2026-102413, rated 6.2. This vulnerability could cause repeated crashes when processing specially crafted filenames under certain Windows locales, including Chinese, Japanese, and Korean. Such crashes could compromise or disable malware prevention and behavioral detection capabilities.

Elastic had already remediated the Kibana flaw in its Cloud Serverless offering prior to public disclosure.

What You Should Do

  • Immediately apply the latest security patches to your Elastic deployments. For Kibana, upgrade to versions 8.19.22, 9.4.7, or 9.5.4. For Elasticsearch, upgrade to 8.19.23, 9.4.8, or 9.5.5.
  • Review the official Elastic security advisories and upgrade notes for detailed instructions and potential post-upgrade steps.
  • Until Kibana can be patched, restrict the ability to upload custom Fleet integration packages to only full superusers.
  • Administrators should meticulously examine all uploaded Fleet packages for any indication of reused datasets or unexpected modifications to existing ingest pipelines.
  • If the Kibana data interception flaw (CVE-2026-102406) is suspected to have been exploited, conduct a thorough forensic investigation of affected infrastructure to ensure complete remediation beyond just package removal.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurity

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

US Offers $10M Reward for APT41 Hacker Over COVID-19 Research Theft

Next Post

Anthropic Claude Haiku 5.5 Offers Enhanced Coding and Computer Vision

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Attackers Hijack .gh, .sl, .as Domain Registries for Rogue HTTPS Certificates
October 7, 2026
CyberXero Blends AI Tools Claude Code, PentAGI with Cobalt Strike for Attacks
October 7, 2026
CrowdStrike, AWS, NVIDIA Expand Cybersecurity Startup Accelerator
October 7, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us