# Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-197)

**URL:** <https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-197/390871>\
**Category:** Security Announcements\
**Created:** [October 6, 2026, 6:51pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-197/390871 "2026-10-06T18:51:14Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [October 6, 2026, 6:51pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-197/390871/1 "2026-10-06T18:51:14Z")

</div>

**Incorrect Authorization in Elasticsearch Leading to Privilege Escalation**

Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks.

Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster.

**Affected Versions:**

> - 8.x: All versions from 8.16.0 up to and including 8.19.21
> - 9.x:

- All versions from 9.0.0 up to and including 9.4.6
- All versions from 9.5.0 up to and including 9.5.3

**Affected Configurations:**

> - This issue only affects deployments that use the configurable delegated role-management privilege ("manage\_roles") where the index names in that privilege include wildcard or regular-expression patterns that can match restricted or system indices (for example `*`, `*kibana*`, or `/.*/`). Deployments that do not use this feature, or that scope such delegations only to literal index names, are not affected. This feature is not available on Elastic Cloud Serverless.

**Solutions and Mitigations:**

The issue is resolved in versions 8.19.22, 9.4.7, and 9.5.4.

The versions above are the first releases verified to contain the fix. Elastic recommends upgrading to one of these fixed versions or a later release verified to contain the fix, and reviewing the known issues for your target version before upgrading.

**For Users that Cannot Upgrade:**

> - **Self-hosted and Elastic Cloud Hosted:** Review any roles that grant the delegated role-management privilege and ensure their configured index names do not use wildcard or regular-expression patterns that could match system or restricted indices. Restrict such grants to literal index names, or remove the privilege from roles assigned to users who should not be able to expand their own access. Audit existing roles created through this feature for unexpected access to restricted or internal indices.

**Indicators of Compromise (IOC)**

Review security audit logs for role or user modifications performed by accounts holding the delegated role-management privilege, particularly where the resulting role or user was subsequently used to access restricted system indices or was granted elevated (e.g. superuser-equivalent) privileges.

**Elastic Cloud Serverless**

This vulnerability does not apply to Elastic Cloud Serverless, where the affected feature is not available.

**Severity:** CVSSv3.1: High ( 7.2 ) - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H  
**CVE ID:** CVE-2026-103007  
**Problem Type:** CWE-863 - Incorrect Authorization
