Authorization Bypass Vulnerability in Elasticsearch by Elastic
CVE-2026-103009

7.1HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-103009?

Elasticsearch is affected by an authorization bypass vulnerability that arises during cross-cluster search operations. This flaw allows users with access to one index through the cross-cluster API to manipulate requests in a way that breaching access controls. Specifically, an attacker can create a cross-cluster search request with differing identifiers, submitting one for authorization while covertly referencing another unauthorized index. This can lead to the exposure of sensitive information contained within that index, including document contents, field mappings, and metadata. Moreover, in limited scenarios, it may even grant the ability to modify retention-lease states on unauthorized indices.

Affected Version(s)

Elasticsearch 8.13.0 <= 8.19.22

Elasticsearch 9.0.0 <= 9.4.7

Elasticsearch 9.5.0 <= 9.5.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.