VORANT. Threat Intelligence Research Sign in Create a free account

CERT-FR Warns of Multiple Elastic Vulnerabilities

routine vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advises patching Elasticsearch and Kibana for multiple vulnerabilities enabling privilege escalation, DoS, and data confidentiality breaches.

CERT-FR has issued an advisory covering multiple vulnerabilities discovered in Elastic products, specifically Elasticsearch and Kibana. The affected versions span Elasticsearch 8.19.x prior to 8.19.22, 9.4.x prior to 9.4.7, and 9.5.x prior to 9.5.4, as well as Kibana 9.5.x prior to 9.5.3, 9.x prior to 9.4.7, and versions prior to 8.19.22. These vulnerabilities collectively could allow an attacker to achieve privilege escalation, cause a remote denial of service, breach data confidentiality, compromise data integrity, or bypass security policies.

The advisory references eleven CVEs (CVE-2026-72662, CVE-2026-72668, CVE-2026-78582, CVE-2026-82294, CVE-2026-82300, CVE-2026-94396, CVE-2026-94397, CVE-2026-94398, CVE-2026-94399, CVE-2026-94400, and CVE-2026-94408) tied to a series of Elastic security bulletins (ESA-2026-85, ESA-2026-103, ESA-2026-139, ESA-2026-170, ESA-2026-176, ESA-2026-179 through ESA-2026-184) all published by Elastic on 25 September 2026. No specific exploitation in the wild is mentioned in this advisory; it functions as a standard vulnerability disclosure and patch notification.

Defenders running Elasticsearch or Kibana should consult the referenced Elastic security bulletins to identify which CVEs apply to their specific deployed versions and apply the corresponding patched releases (Elasticsearch 8.19.22/9.4.7/9.5.4 and Kibana 8.19.22/9.4.7/9.5.3 or later) as soon as possible, particularly given the privilege escalation and remote DoS impact categories.

Mentioned in this report

Vulnerabilities CVE-2026-72662CVE-2026-72668CVE-2026-78582CVE-2026-82294CVE-2026-82300CVE-2026-94396CVE-2026-94397CVE-2026-94398CVE-2026-94399CVE-2026-94400CVE-2026-94408

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1228

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,138 reports from 155 sources, 1,776 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs