Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, to claim a data stream identifier already in use by another tenant. Because ownership of that identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, an attacker could redirect an existing tenant's data stream through infrastructure under their control. This exposed the affected tenant's subsequently ingested data to unauthorized disclosure and modification, and prevented that data from reaching its intended destination. Interception could continue even after the malicious package was removed, requiring separate remediation of the affected infrastructure.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Cross‑tenant data interception and potential tampering
Action: Assess Impact
AI Analysis

Impact

An authorization bypass (CWE‑639) in Kibana’s Fleet package installation allows a user with delegated package‑management rights to claim a data stream identifier already in use by another tenant. By not verifying ownership before applying the configuration, the tenant’s data stream can be redirected to infrastructure controlled by the attacker, exposing subsequent data to unauthorized disclosure, tampering, and preventing it from reaching its intended destination. The flaw can persist even after the malicious package is removed, requiring additional remediation of affected infrastructure.

Affected Systems

Elastic Kibana deployments that employ the Fleet package installation process are vulnerable. The affected product is Kibana by Elastic, with no specific version information provided in the advisory. Any instance where a user holds delegated Fleet package‑management privileges without full Elasticsearch administrative rights may be susceptible.

Risk and Exploitability

With a CVSS score of 8.8, this vulnerability is rated high severity, and its EPSS score is not available, so current exploitation probability is unknown. The flaw is not listed in the CISA KEV catalog. The likely attack vector is an internal actor leveraging legitimate delegated permissions to claim a data stream identifier. Successful exploitation could allow the attacker to intercept and, potentially, modify the data of another tenant, and the impact persists even if the malicious package is later removed, reflecting the need for careful infrastructure review.

Generated by OpenCVE AI on October 6, 2026 at 20:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to the latest Kibana release that contains the fix.
  • Restrict or revoke delegated Fleet package‑management privileges to prevent unauthorized claims of data streams.
  • Audit all existing data stream identifiers and ingest pipelines to detect misaligned ownership, and reconfigure or delete any that have been redirected to unauthorized infrastructure.
  • Temporarily suspend affected data streams or remove the malicious package until the infrastructure is cleaned and re‑validated.

Generated by OpenCVE AI on October 6, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, to claim a data stream identifier already in use by another tenant. Because ownership of that identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, an attacker could redirect an existing tenant's data stream through infrastructure under their control. This exposed the affected tenant's subsequently ingested data to unauthorized disclosure and modification, and prevented that data from reaching its intended destination. Interception could continue even after the malicious package was removed, requiring separate remediation of the affected infrastructure.
Title Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:56:58.361Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102406

cve-icon Vulnrichment

Updated: 2026-10-06T19:56:53.435Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:12.480

Modified: 2026-10-06T20:17:12.480

Link: CVE-2026-102406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key