Skip to content
cve — cve-2026-102406

grep -rl "CVE-2026-102406" ./articles

CVE-2026-102406

A Kibana user with delegated package-management rights, and no Elasticsearch administrative privileges, could install a package that claimed a data stream identifier already belonging to someone else. Ownership was never checked, so another tenant's telemetry could be redirected through infrastructure the attacker controlled.

1 article — 2026-10-08

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered