Elastic Publishes Ten Elasticsearch Security Advisories
Quick Answer
Elastic published ESA-2026-185 and ESA-2026-188 and ESA-2026-189 and ESA-2026-190 and ESA-2026-192 and ESA-2026-195 and ESA-2026-196 and ESA-2026-197 and ESA-2026-198 and ESA-2026-199 for Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions. Inventory the exact affected scope, apply Elasticsearch 8.19.23, 9.4.8, or 9.5.5 for the broadest combined coverage, while following each ESA's branch-specific fixed version, validate dependent operations, and preserve change evidence.
Validate Elasticsearch Scope And Apply The Supported Fix
What to do now: Inventory Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions, match versions and enabled features to the authority's scope, apply supported remediation, validate representative operations, and document exceptions.
Last verified: 2026-10-07 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions |
|---|---|
| Advisory | ESA-2026-185 / ESA-2026-188 / ESA-2026-189 / ESA-2026-190 / ESA-2026-192 / ESA-2026-195 / ESA-2026-196 / ESA-2026-197 / ESA-2026-198 / ESA-2026-199 |
| CVEs | CVE-2026-102404, CVE-2026-102407, CVE-2026-102408, CVE-2026-102409, CVE-2026-102411, CVE-2026-103005, CVE-2026-103006, CVE-2026-103007, CVE-2026-103008, CVE-2026-103009 |
| Authoritative release date | 2026-10-06 18:34:51 UTC |
| Authority revision date | 2026-10-06 18:53:21 UTC |
| Affected versions | The advisory-specific Elasticsearch ranges and enabled ES|QL, templates, connectors, aggregations, delegated role management, runtime fields, or remote-cluster-search features. |
| Fixed version | Elasticsearch 8.19.23, 9.4.8, or 9.5.5 for the broadest combined coverage, while following each ESA's branch-specific fixed version |
| CVSS base score | 4.3 / 5.4 / 6.5 / 7.1 / 7.2 (CVSS v3.1) |
| CVSS severity | Medium to High |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Elastic corrected denial-of-service conditions, unauthorized data-stream modification, a delegated manage_roles privilege boundary issue, and an RCS 2.0 cross-cluster authorization bypass.
What To Validate Now
- Inventory. Locate Elasticsearch 7.17, 8.19, 9.3, 9.4, and 9.5 branches under the advisory-specific version and feature conditions; record versions, enabled features, exposure paths, owners, dependencies, support channels, and maintenance groups.
- Establish applicability. Compare every deployment with the authority's affected statement: The advisory-specific Elasticsearch ranges and enabled ES|QL, templates, connectors, aggregations, delegated role management, runtime fields, or remote-cluster-search features. Do not infer applicability from product family, CVSS, or Internet reachability alone.
- Remediate. Apply Elasticsearch 8.19.23, 9.4.8, or 9.5.5 for the broadest combined coverage, while following each ESA's branch-specific fixed version through the authority-supported channel and follow the current advisory.
- Validate. Confirm the resulting Elasticsearch build or managed state, exercise representative services and recovery paths, monitor for regressions, and retain the result.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Review the individual ESA version ranges. If immediate upgrades are impossible, use only the ESA-stated workaround, including disabling remote clusters for ESA-2026-199 or restricting delegated role patterns for ESA-2026-197. Preserve pre-change state, installation output, logs, validation evidence, and rollback decisions.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
- ESA-2026-185
- ESA-2026-188
- ESA-2026-189
- ESA-2026-190
- ESA-2026-192
- ESA-2026-195
- ESA-2026-196
- ESA-2026-197
- ESA-2026-198
- ESA-2026-199
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

