Description
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster.
Published: 2026-10-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Update
AI Analysis

Impact

A mis‑implementation of authorization controls in Elasticsearch, identified as CWE‑863, allows an administrator to delegate a privileged role that is intended to be restricted to specific indices. The enforcement of index scoping during delegation fails to consider a role‑definition setting that can expand the matched index set. Consequently, a user holding this delegated privilege can modify their assigned role to gain access to additional indices that should remain protected, potentially including internal security data. This flaw enables an attacker to increase their privileges incrementally up to full administrative control of the cluster.

Affected Systems

The vulnerability affects Elasticsearch implementations. Security updates that address this issue are available in release branches 8.19.22, 9.4.7, and 9.5.4. All earlier releases that did not incorporate the patch are susceptible.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. While an EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests limited known active exploitation. The flaw is likely exploitable via the cluster’s internal REST API or via any interface that allows an administrator to modify role definitions, such as Kibana management console or direct role API calls. An attacker who can gain the delegated privilege can adjust role assignments to access restricted data and progressively increase privileges.

Generated by OpenCVE AI on October 6, 2026 at 20:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Elasticsearch to a patched release that incorporates the authorization fix, such as 8.19.22, 9.4.7, or 9.5.4.
  • Limit or disable the use of delegated administrative privileges that allow role‑management on restricted indices.
  • Configure role definitions to ensure that index patterns cannot be expanded beyond their intended scope, removing any settings that enable such expansion.

Generated by OpenCVE AI on October 6, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster.
Title Incorrect Authorization in Elasticsearch Leading to Privilege Escalation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:52:59.438Z

Reserved: 2026-09-29T20:57:38.467Z

Link: CVE-2026-103007

cve-icon Vulnrichment

Updated: 2026-10-06T19:52:54.565Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:13.930

Modified: 2026-10-06T20:17:13.930

Link: CVE-2026-103007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses