Elasticsearch 中存在不正确的授权(CWE-863)漏洞,可能通过“访问未被访问控制列表(ACL)适当限制的功能”(CAPEC-1)导致数据流被未授权修改。具有足够权限的已认证用户可能利用 Modify Data Streams API 修改其本无权限访问的数据流,从而向该数据流注入数据或影响其正常搜索能力。此漏洞不允许攻击者读取其本身无权访问的数据流内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 7.17.5≤ 7.17.29 |
affected |
8.2.2≤ 8.19.18 |
affected | ||
9.0.0≤ 9.3.7 |
affected | ||
9.4.0≤ 9.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 7.17.5 ~ 7.17.29 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102406 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data In |
| CVE-2026-103007 | 7.2 HIGH | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation |
| CVE-2026-103009 | 7.1 HIGH | Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information D |
| CVE-2026-102412 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-102409 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102411 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-102404 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-103008 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-103005 | 6.5 MEDIUM | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
| CVE-2026-103006 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102413 | 6.2 MEDIUM | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-102410 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-102408 | 4.3 MEDIUM | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service |
No comments yet