Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check validates a request against one identifying attribute of the target shard, while a separate, independently-supplied identifying attribute in the same request determines which shard is actually accessed. A holder of a cross-cluster API key authorized for one index can craft a request whose two identifying attributes refer to different indices, causing the request to be authorized against an index they can access while actually operating against a different, unauthorized index. This can expose that index's document contents, field mappings, and other metadata, and in limited cases allows modification of retention-lease state on the unauthorized index.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Information Disclosure via Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

An authorization bypass flaw (CWE‑639) exists in Elasticsearch’s handling of cross‑cluster search requests via the Remote Cluster Security 2.0 model. The flaw allows an attacker holding an API key that is permitted to search a specific index to craft a request in which the identifying attribute used for authorization differs from the attribute that determines the actual target shard. As a result, the request is authorized against a legitimate index while accessing a different, unauthorized index, potentially exposing that index’s documents, field mappings, and metadata. In some scenarios the attacker can also alter retention‑lease state on the unauthorized index.

Affected Systems

Elastic: Elasticsearch is affected. The CVE does not list specific affected releases or patch numbers, so the risk applies to any Elasticsearch deployment that uses the Remote Cluster Security 2.0 model for cross‑cluster search.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is unclear. The likely attack vector involves an attacker leveraging an existing RCS 2.0 authorized API key to submit a crafted request; once authorized, the impact is full data disclosure and limited write capability on a target index.

Generated by OpenCVE AI on October 6, 2026 at 20:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Elasticsearch release that contains the security update for EA‑2026‑199, as detailed in Elastic’s advisory.
  • Disable or revoke Remote Cluster Security 2.0 cross‑cluster search capabilities until the patch is applied.
  • Restrict API keys to the minimal set of indices and regularly audit key permissions to ensure no key has unintended cross‑index access.

Generated by OpenCVE AI on October 6, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check validates a request against one identifying attribute of the target shard, while a separate, independently-supplied identifying attribute in the same request determines which shard is actually accessed. A holder of a cross-cluster API key authorized for one index can craft a request whose two identifying attributes refer to different indices, causing the request to be authorized against an index they can access while actually operating against a different, unauthorized index. This can expose that index's document contents, field mappings, and other metadata, and in limited cases allows modification of retention-lease state on the unauthorized index.
Title Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:52:13.370Z

Reserved: 2026-09-29T20:57:38.467Z

Link: CVE-2026-103009

cve-icon Vulnrichment

Updated: 2026-10-06T19:52:10.160Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:14.247

Modified: 2026-10-06T20:17:14.247

Link: CVE-2026-103009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:00:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key