# CERT-FR Warns of Multiple Elastic Vulnerabilities

Published: 2026-09-25 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/0e1e7697-3790-5806-8d50-94912308a22b/cert-fr-warns-of-multiple-elastic-vulnerabilities

> CERT-FR advises patching Elasticsearch and Kibana for multiple vulnerabilities enabling privilege escalation, DoS, and data confidentiality breaches.

CERT-FR has issued an advisory covering multiple vulnerabilities discovered in Elastic products, specifically Elasticsearch and Kibana. The affected versions span Elasticsearch 8.19.x prior to 8.19.22, 9.4.x prior to 9.4.7, and 9.5.x prior to 9.5.4, as well as Kibana 9.5.x prior to 9.5.3, 9.x prior to 9.4.7, and versions prior to 8.19.22. These vulnerabilities collectively could allow an attacker to achieve privilege escalation, cause a remote denial of service, breach data confidentiality, compromise data integrity, or bypass security policies.

The advisory references eleven CVEs (CVE-2026-72662, CVE-2026-72668, CVE-2026-78582, CVE-2026-82294, CVE-2026-82300, CVE-2026-94396, CVE-2026-94397, CVE-2026-94398, CVE-2026-94399, CVE-2026-94400, and CVE-2026-94408) tied to a series of Elastic security bulletins (ESA-2026-85, ESA-2026-103, ESA-2026-139, ESA-2026-170, ESA-2026-176, ESA-2026-179 through ESA-2026-184) all published by Elastic on 25 September 2026. No specific exploitation in the wild is mentioned in this advisory; it functions as a standard vulnerability disclosure and patch notification.

Defenders running Elasticsearch or Kibana should consult the referenced Elastic security bulletins to identify which CVEs apply to their specific deployed versions and apply the corresponding patched releases (Elasticsearch 8.19.22/9.4.7/9.5.4 and Kibana 8.19.22/9.4.7/9.5.3 or later) as soon as possible, particularly given the privilege escalation and remote DoS impact categories.

## Mentioned in this report

- Vulnerabilities: CVE-2026-72662, CVE-2026-72668, CVE-2026-78582, CVE-2026-82294, CVE-2026-82300, CVE-2026-94396, CVE-2026-94397, CVE-2026-94398, CVE-2026-94399, CVE-2026-94400, CVE-2026-94408

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1228

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0e1e7697-3790-5806-8d50-94912308a22b/cert-fr-warns-of-multiple-elastic-vulnerabilities.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
