CERT-FR flags multiple Elastic Stack vulnerabilities
CERT-FR advisory lists numerous vulnerabilities across Elastic products including Elasticsearch, Kibana, APM Server, and Fleet Server that could enable RCE, privilege escalation, and data exposure.
CERT-FR published an advisory (CERTFR-2026-AVI-1107) consolidating multiple vulnerabilities discovered across the Elastic product suite, including Elasticsearch, Kibana, APM Server, Elastic Agent, Fleet Server, Filebeat, Winlogbeat, Elastic Maps Server, and Elastic Cloud on Kubernetes. The flaws span a range of impact types: remote code execution, privilege escalation, data confidentiality breaches, data integrity violations, security policy bypass, remote denial of service, and SQL injection. Numerous CVEs are referenced, most dated 2026 with one legacy reference to CVE-2015-5531 and CVE-2024-14047.
Affected version ranges are broad, covering multiple release branches (8.x and 9.x series) across nearly every major Elastic component, indicating this is a consolidated patch cycle addressing many distinct issues rather than a single exploited flaw. No indicators of compromise, active exploitation, or attributed threat actor activity are mentioned in the advisory; it is a vendor-coordinated disclosure and patch release tracked by CERT-FR.
Defenders running any Elastic Stack components should review the specific bulletins linked in the advisory to identify which CVEs apply to their deployed versions and prioritize patching, particularly for RCE and privilege escalation-capable issues in internet-facing services like Kibana, Elasticsearch, and Fleet Server. No public exploitation has been reported at time of advisory publication.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1107
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free