Improper Authorization in Elasticsearch by Elastic
CVE-2026-103007

7.2HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-103007?

Elasticsearch contains a flaw that allows for privilege escalation through incorrect authorization management. Administrators can delegate role management capabilities to users scoped to specific indices, but the authorization checks fail to fully enforce these limitations. This inconsistency allows users with broad index patterns to exploit their delegated privileges. As a result, they may update roles to gain access to restricted indices, risking exposure of sensitive internal security data and potentially escalating their control to full administrative privileges over the cluster.

Affected Version(s)

Elasticsearch 8.16.0 <= 8.19.21

Elasticsearch 9.0.0 <= 9.4.6

Elasticsearch 9.5.0 <= 9.5.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.