Authorization Bypass Vulnerability in Elasticsearch by Elastic
CVE-2026-103009
What is CVE-2026-103009?
Elasticsearch is affected by an authorization bypass vulnerability that arises during cross-cluster search operations. This flaw allows users with access to one index through the cross-cluster API to manipulate requests in a way that breaching access controls. Specifically, an attacker can create a cross-cluster search request with differing identifiers, submitting one for authorization while covertly referencing another unauthorized index. This can lead to the exposure of sensitive information contained within that index, including document contents, field mappings, and metadata. Moreover, in limited scenarios, it may even grant the ability to modify retention-lease states on unauthorized indices.
Affected Version(s)
Elasticsearch 8.13.0 <= 8.19.22
Elasticsearch 9.0.0 <= 9.4.7
Elasticsearch 9.5.0 <= 9.5.4