Multiples vulnérabilités dans les produits Elastic (22 juillet 2026)
Multiple vulnerabilities have been discovered in Elastic products, including Elasticsearch and Kibana. These vulnerabilities can lead to data integrity compromise, data confidentiality breaches, and denial-of-service attacks. Several CVEs are associated with these issues, including CVE-2018-17245, CVE-2026-42397, CVE-2026-49092, CVE-2026-56144, CVE-2026-56145, CVE-2026-56146, CVE-2026-56147, CVE-2026-63136, CVE-2026-63139, CVE-2026-63140, CVE-2026-63141, CVE-2026-63142, CVE-2026-63143, CVE-2026-63144, CVE-2026-63145, CVE-2026-63259, CVE-2026-63260, CVE-2026-63261, CVE-2026-63262, and CVE-2026-63263. Elastic recommends users update to the latest versions to mitigate these risks.
Multiple vulnerabilities have been identified within Elastic's Elasticsearch and Kibana products. These vulnerabilities pose significant risks to data integrity, confidentiality, and availability. Specifically, the vulnerabilities can lead to data integrity compromise, data confidentiality breaches, and denial-of-service attacks.
**What happened**
Elastic has released security updates addressing a range of vulnerabilities. These include issues related to SSRF (Server-Side Request Forgery), allowing an attacker to cause a denial-of-service attack. The vulnerabilities affect Elasticsearch versions 8.x prior to 8.19.19, Elasticsearch versions 9.4.x prior to 9.4.4, Elasticsearch versions 9.x prior to 9.3.8, Kibana versions 8.x prior to 8.19.19, Kibana versions 9.4.x prior to 9.4.4, and Kibana versions 9.x prior to 9.3.8. The vulnerabilities include CVE-2018-17245, CVE-2026-42397, CVE-2026-49092, CVE-2026-56144, CVE-2026-56145, CVE-2026-56146, CVE-2026-56147, CVE-2026-63136, CVE-2026-63139, CVE-2026-63140, CVE-2026-63141, CVE-2026-63142, CVE-2026-63143, CVE-2026-63144, CVE-2026-63145, CVE-2026-63259, CVE-2026-63260, CVE-2026-63261, CVE-2026-63262, and CVE-2026-63263. The vulnerabilities are related to SSRF and can be exploited to cause a denial-of-service attack, potentially leading to service disruption.
**Technical details**
- **Affected Products:** Elasticsearch versions 8.x (prior to 8.19.19), Elasticsearch versions 9.4.x (prior to 9.4.4), Elasticsearch versions 9.x (prior to 9.3.8), Kibana versions 8.x (prior to 8.19.19), Kibana versions 9.4.x (prior to 9.4.4), Kibana versions 9.x (prior to 9.3.8).
- **Attack Vector:** SSRF.
- **Exploitation Status:** Exploitation is possible.
- **CVSS Score:** Varies depending on the specific CVE.
**Impact**
The exploitation of these vulnerabilities could lead to data integrity compromise, data confidentiality breaches, and denial-of-service attacks. This could result in unauthorized access to sensitive data, disruption of services, and potential damage to Elastic's products and services. The vulnerabilities could be used to execute arbitrary code, potentially leading to a complete system takeover.
**What to do**
- Refer to the Elastic Security Bulletin for the latest updates and instructions: [https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553](https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553)
- Refer to the Elastic Security Bulletin for the latest updates and instructions: [https://discuss.elastic.co/t/elasticsearch-8-19-18-9-3-7-9-4-4-security-update-esa-2026-56/388556](https://discuss.elastic.co/t/elasticsearch-8-19-18-9-3-7-9-4-4-security-update-esa-2026-56/388556)
- Refer to the Elastic Security Bulletin for the latest updates and instructions: [https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-58/388557](https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-58/388557)
- Refer to the Elastic Security Bulletin for the latest updates and instructions: [https://discuss.elastic.co/t/elasticsearch-8-19-18-9-3-7-9-4-4-security-update-esa-2026-64/388565](https://discuss.elastic.co/t/elasticsearch-8-19-18-9-3-7-9-4-4-security-update-esa-2026-64/388565)
- Refer to the Elastic Security Bulletin for the latest updates and instructions: [https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-70/388573](https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-70/388573)
**Why it matters**
Elastic's products are widely used for log management, security analytics, and business intelligence. A successful attack could expose sensitive data, disrupt critical services, and undermine trust in Elastic's offerings. Prompt patching and proactive monitoring are crucial to mitigate these risks and ensure the security and stability of Elastic's ecosystem.