Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster. | |
| Title | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-10-06T19:52:59.438Z
Reserved: 2026-09-29T20:57:38.467Z
Link: CVE-2026-103007
Updated: 2026-10-06T19:52:54.565Z
Status : Received
Published: 2026-10-06T20:17:13.930
Modified: 2026-10-06T20:17:13.930
Link: CVE-2026-103007
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:30:05Z