Multiple vulnerabilities in Elastic products (02 September 2026)
Multiple vulnerabilities were discovered in Elastic products. Some of them allow an attacker to cause arbitrary remote code execution, privilege escalation and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Elastic products allow remote code execution, privilege escalation, and data confidentiality breaches.
- Who is affected
- Deployments of affected Elastic products are vulnerable.
- Urgency
- High urgency due to remote code execution and privilege escalation risks, though no exploitation has been reported.
- Action
- Consult the published Elastic security advisory for affected product versions and apply available patches immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1107/
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-82293: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthori…nvd
- mediumCVE-2026-78609: Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorize…nvd
- highCVE-2026-78604: Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to l…nvd
- mediumCVE-2026-78602: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Ela…nvd
- mediumCVE-2026-78601: Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abu…nvd
- lowCVE-2026-78600: Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized acc…nvd
- mediumCVE-2026-78599: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the…nvd
- mediumCVE-2026-78598: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to informati…nvd
- mediumCVE-2026-78594: Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent d…nvd
- mediumCVE-2026-78591: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the…nvd
- highCVE-2026-78590: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the…nvd
- mediumCVE-2026-78588: Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denia…nvd
Recent advisories for Elastic products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Elastic products (July 22, 2026)cert-fr-avis · 2026-07-22
- highCVE-2026-61053: Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Com…nvd · 2026-07-21
- unknownMultiple vulnerabilities in Elastic products (July 2, 2026)cert-fr-avis · 2026-07-02
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Curl (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in HPE Aruba Networking products (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Google Chrome (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Mozilla products (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in SonicWall products (02 September 2026)2026-09-02