logo

Elastic Stack Under Fire: 7 New Flaws Expose Files & Crash Servers

ID: cd3debda-5ac9-591d-96d6-36c38d6cffd3

STIX ID: report--cd3debda-5ac9-591d-96d6-36c38d6cffd3

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Elastic released security updates addressing seven vulnerabilities across Elasticsearch, Kibana, Packetbeat, and Metricbeat — notably CVE-2026-0532 (Google Gemini connector SSRF and arbitrary file disclosure, CVSS 8.6) and an LZ4-based information disclosure in Elasticsearch (CVSS 8.4). The advisory also fixes multiple DoS flaws in Kibana and buffer/validation issues in Beats; administrators are urged to upgrade to 8.19.10, 9.1.10, or 9.2.4 or apply the recommended mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.