Elasticsearch 中的错误授权(CWE-863)可能导致通过代理管理员特权实现的权限提升。该特权的范围在授权检查过程中未得到完全执行。Elasticsearch 中存在一个配置化的、非默认的特权,允许管理员将有限的角色管理能力委托给另一个用户,且该能力的作用范围限定为特定的索引。然而,执行此范围限制的授权检查未能正确考虑某些角色定义设置,这些设置可以扩大匹配的索引集合。拥有此代理特权且使用广泛匹配的索引模式的用户,可以通过更新自己分配的角色来利用这一不一致性,从而访问本应受限制的索引,包括内部安全数据。这
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 8.16.0≤ 8.19.21 |
affected |
9.0.0≤ 9.4.6 |
affected | ||
9.5.0≤ 9.5.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 8.16.0 ~ 8.19.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102406 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data In |
| CVE-2026-103009 | 7.1 HIGH | Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information D |
| CVE-2026-102412 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-102409 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102411 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-102404 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-103008 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-103005 | 6.5 MEDIUM | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
| CVE-2026-103006 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102413 | 6.2 MEDIUM | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-102407 | 5.4 MEDIUM | Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification |
| CVE-2026-102410 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-102408 | 4.3 MEDIUM | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service |
No comments yet