news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits Elastic (02 septembre 2026)

HighCVSS 8.8
Summary

Multiple vulnerabilities have been discovered in Elastic products. Some of these vulnerabilities allow an attacker to cause arbitrary code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities affect a wide range of Elastic products including Elasticsearch, Kibana, Logstash, Filebeat, Metricbeat, APM Server, Fleet Server, Elastic Cloud on Kubernetes, and Elastic Maps Server. Several CVEs have been identified, including CVE-2015-5531, CVE-2024-14047, CVE-2026-63137, and others. Elastic has released security updates to address these issues.

Multiple vulnerabilities have been discovered in Elastic products, requiring immediate attention. These vulnerabilities can lead to data integrity compromise, confidentiality breaches, and denial of service attacks. Specifically, the Elastic products affected include Elasticsearch, Kibana, Logstash, Filebeat, Metricbeat, APM Server, Fleet Server, Elastic Cloud on Kubernetes, and Elastic Maps Server.

APM Server versions 8.19.x through 8.19.20, 9.4.x through 9.4.5, and 9.5.x through 9.5.1 are impacted. Elastic Agent versions 8.19.x through 8.19.21 and 9.4.x through 9.4.6, and 9.5.x through 9.5.2 are also vulnerable. Elastic Cloud on Kubernetes versions prior to 3.5.0, Elastic Maps Server versions 8.19.x through 8.19.19, 9.4.x through 9.4.4, and 9.5.x through 9.5.1, and Filebeat versions 8.19.x through 8.19.18, 9.x through 9.3.1, Fleet Server versions 8.x through 8.19.16, 9.4.x through 9.4.2, and 9.x through 9.3.5, and Kibana versions 8.19.21, 9.4.6, 9.5.2, and 8.19.16, 9.3.5, 9.4.2, and 8.19.18, 9.3.6, 9.4.3, 9.4.4, and 8.19.19, 9.3.8, 9.4.5, 9.5.1, and Elasticsearch versions 8.x through 8.19.20, 9.4.x through 9.4.5, and 9.5.x through 9.5.1 are all affected. Several CVEs have been identified, including CVE-2015-5531, CVE-2024-14047, CVE-2026-63137, CVE-2026-72628, CVE-2026-72641, CVE-2026-72644, CVE-2026-78584, CVE-2026-78586, CVE-2026-78587, CVE-2026-78588, CVE-2026-78590, CVE-2026-78591, CVE-2026-78592, CVE-2026-78594, and CVE-2026-78597, among others. Elastic has released security updates to address these issues. Refer to the Elastic Security Bulletin for detailed information and instructions on how to apply the fixes. The Elastic Security Bulletin can be found at: https://discuss.elastic.co/t/winlogbeat-8-13-0-security-update-esa-2024-49/390044, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-135/390119, and other links provided in the Elastic Security Bulletin.

Read the full article at CERT-FR