Elastic Publishes Ten Elasticsearch Security Advisories

P1 — VALIDATE AND UPDATEMedium to High · 4.3 / 5.4 / 6.5 / 7.1 / 7.2 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Elastic published ESA-2026-185 and ESA-2026-188 and ESA-2026-189 and ESA-2026-190 and ESA-2026-192 and ESA-2026-195 and ESA-2026-196 and ESA-2026-197 and ESA-2026-198 and ESA-2026-199 for Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions. Inventory the exact affected scope, apply Elasticsearch 8.19.23, 9.4.8, or 9.5.5 for the broadest combined coverage, while following each ESA's branch-specific fixed version, validate dependent operations, and preserve change evidence.

Validate Elasticsearch Scope And Apply The Supported Fix

What to do now: Inventory Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions, match versions and enabled features to the authority's scope, apply supported remediation, validate representative operations, and document exceptions.

Open the authoritative advisory

Last verified: 2026-10-07 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeElasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions
AdvisoryESA-2026-185 / ESA-2026-188 / ESA-2026-189 / ESA-2026-190 / ESA-2026-192 / ESA-2026-195 / ESA-2026-196 / ESA-2026-197 / ESA-2026-198 / ESA-2026-199
CVEsCVE-2026-102404, CVE-2026-102407, CVE-2026-102408, CVE-2026-102409, CVE-2026-102411, CVE-2026-103005, CVE-2026-103006, CVE-2026-103007, CVE-2026-103008, CVE-2026-103009
Authoritative release date2026-10-06 18:34:51 UTC
Authority revision date2026-10-06 18:53:21 UTC
Affected versionsThe advisory-specific Elasticsearch ranges and enabled ES|QL, templates, connectors, aggregations, delegated role management, runtime fields, or remote-cluster-search features.
Fixed versionElasticsearch 8.19.23, 9.4.8, or 9.5.5 for the broadest combined coverage, while following each ESA's branch-specific fixed version
CVSS base score4.3 / 5.4 / 6.5 / 7.1 / 7.2 (CVSS v3.1)
CVSS severityMedium to High
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Elastic corrected denial-of-service conditions, unauthorized data-stream modification, a delegated manage_roles privilege boundary issue, and an RCS 2.0 cross-cluster authorization bypass.

What To Validate Now

  1. Inventory. Locate Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions; record versions, enabled features, exposure paths, owners, dependencies, support channels, and maintenance groups.
  2. Establish applicability. Compare every deployment with the authority's affected statement: The advisory-specific Elasticsearch ranges and enabled ES|QL, templates, connectors, aggregations, delegated role management, runtime fields, or remote-cluster-search features. Do not infer applicability from product family, CVSS, or Internet reachability alone.
  3. Remediate. Apply Elasticsearch 8.19.23, 9.4.8, or 9.5.5 for the broadest combined coverage, while following each ESA's branch-specific fixed version through the authority-supported channel and follow the current advisory.
  4. Validate. Confirm the resulting Elasticsearch build or managed state, exercise representative services and recovery paths, monitor for regressions, and retain the result.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Review the individual ESA version ranges. If immediate upgrades are impossible, use only the ESA-stated workaround, including disabling remote clusters for ESA-2026-199 or restricting delegated role patterns for ESA-2026-197. Preserve pre-change state, installation output, logs, validation evidence, and rollback decisions.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.