# Elastic patches multiple Elasticsearch, Kibana flaws

Published: 2026-07-22 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/afc4576b-93fb-56df-b8a5-65a1b55b4b57/elastic-patches-multiple-elasticsearch-kibana-flaws

> ANSSI advisory details multiple vulnerabilities in Elasticsearch and Kibana that can enable denial of service, data confidentiality/integrity breaches, and SSRF.

France's CERT-FR (ANSSI) issued an advisory covering a large batch of vulnerabilities affecting Elastic's Elasticsearch and Kibana products across versions 8.x, 9.3.x, and 9.4.x. The flaws span multiple risk categories including remote denial of service, unauthorized data disclosure, data integrity compromise, security policy bypass, and server-side request forgery (SSRF). No evidence of active exploitation is mentioned in the advisory; it is a standard vendor patch notification aggregating numerous Elastic security bulletins (ESA-2026-54 through ESA-2026-74) published on 21 July 2026.

The advisory references a large number of CVEs, including one older entry (CVE-2018-17245) alongside many 2026-dated identifiers, suggesting a consolidated patch release addressing both recently discovered and previously known issues. Organizations running affected Elasticsearch or Kibana versions below the fixed releases (8.19.19, 9.3.8, 9.4.4) should apply vendor patches per the referenced bulletins. Given the breadth of products deployed for search, logging, and observability, unpatched instances could expose sensitive indexed data or disrupt service availability.

## Mentioned in this report

- Vulnerabilities: CVE-2018-17245, CVE-2026-42397, CVE-2026-49092, CVE-2026-56144, CVE-2026-56145, CVE-2026-56146, CVE-2026-56147, CVE-2026-63136, CVE-2026-63139, CVE-2026-63140, CVE-2026-63141, CVE-2026-63142, CVE-2026-63143, CVE-2026-63144, CVE-2026-63145, CVE-2026-63259, CVE-2026-63260, CVE-2026-63261, CVE-2026-63262, CVE-2026-63263

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0906

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/afc4576b-93fb-56df-b8a5-65a1b55b4b57/elastic-patches-multiple-elasticsearch-kibana-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
