CVE-2026-103009
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check validates a request against one identifying attribute of the target shard, while a separate, independently-supplied identifying attribute in the same request determines which shard is actually accessed. A holder of a cross-cluster API key authorized for one index can craft a request whose two identifying attributes refer to different indices, causing the request to be authorized against an index they can access while actually operating against a different, unauthorized index. This can expose that index's document contents, field mappings, and other metadata, and in limited cases allows modification of retention-lease state on the unauthorized index.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-639
- Published
- 2026-10-06
- Last modified
- 2026-10-06
Affected products
- Elastic Elasticsearch
- Elastic Elasticsearch
- Elastic Elasticsearch
Weakness type
Related vulnerabilities
- CVE-2026-105859 — Payload: Unauthorized update to collection documents
- CVE-2026-105639 — Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
- CVE-2026-105637 — Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
- CVE-2026-91107 — openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
- CVE-2026-74864 — Authentication Bypass in sogo_yhn
- CVE-2026-101084 — obot before v0.21.1 Authorization Bypass via /mcp-connect
- CVE-2026-74865 — Authentication Bypass in sogo_yhn
- CVE-2026-93399 — Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter