Improper Authorization in Elasticsearch by Elastic
CVE-2026-103007
7.2HIGH
What is CVE-2026-103007?
Elasticsearch contains a flaw that allows for privilege escalation through incorrect authorization management. Administrators can delegate role management capabilities to users scoped to specific indices, but the authorization checks fail to fully enforce these limitations. This inconsistency allows users with broad index patterns to exploit their delegated privileges. As a result, they may update roles to gain access to restricted indices, risking exposure of sensitive internal security data and potentially escalating their control to full administrative privileges over the cluster.
Affected Version(s)
Elasticsearch 8.16.0 <= 8.19.21
Elasticsearch 9.0.0 <= 9.4.6
Elasticsearch 9.5.0 <= 9.5.3