Elasticsearch 中存在通过用户可控键绕过授权(CWE-639)的漏洞,攻击者可通过构造特制的跨集群搜索请求,引用未授权的片段(shard)标识符,从而导致信息泄露。 在通过远程集群安全(RCS)2.0 模型发起的跨集群搜索请求处理过程中,Elasticsearch 存在授权绕过弱点。授权检查机制基于目标片段的某个识别属性对请求进行验证,而同一请求中另一个独立提供的识别属性则决定实际访问的是哪个片段。持有跨集群 API 密钥且被授权访问某个索引的用户,可以构造一个请求,使其两个识别属性分别指向不同的索引:
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 8.13.0≤ 8.19.22 |
affected |
9.0.0≤ 9.4.7 |
affected | ||
9.5.0≤ 9.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 8.13.0 ~ 8.19.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102406 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data In |
| CVE-2026-103007 | 7.2 HIGH | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation |
| CVE-2026-102412 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-102409 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102411 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-102404 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-103008 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-103005 | 6.5 MEDIUM | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
| CVE-2026-103006 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102413 | 6.2 MEDIUM | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-102407 | 5.4 MEDIUM | Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification |
| CVE-2026-102410 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-102408 | 4.3 MEDIUM | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service |
No comments yet