Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier.
Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check validates a request against one identifying attribute of the target shard, while a separate, independently-supplied identifying attribute in the same request determines which shard is actually accessed. A holder of a cross-cluster API key authorized for one index can craft a request whose two identifying attributes refer to different indices, causing the request to be authorized against an index they can access while actually operating against a different, unauthorized index. This can expose that index's document contents, field mappings, and other metadata, and in limited cases allows modification of retention-lease state on the unauthorized index.
Affected Versions:
- 8.x: All versions from 8.13.0 up to and including 8.19.22
- 9.x:
- All versions from 9.0.0 up to and including 9.4.7
- All versions from 9.5.0 up to and including 9.5.4
Affected Configurations:
- This issue only affects clusters configured as a fulfilling cluster for cross-cluster search using the Remote Cluster Security (RCS) 2.0 model. Deployments that do not expose a remote cluster transport port for cross-cluster search are not affected. This issue is not exploitable via the REST API.
Solutions and Mitigations:
The issue is resolved in versions 8.19.23, 9.4.8, and 9.5.5.
The versions above are the first releases verified to contain the fix. Elastic recommends upgrading to one of these fixed versions or a later release verified to contain the fix, and reviewing the known issues for your target version before upgrading.
For Users that Cannot Upgrade:
- If cross-cluster search using RCS 2.0 is not required, disable remote cluster connections on the fulfilling cluster to remove exposure to this issue.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
This vulnerability does not apply to Elastic Cloud Serverless.
Severity: CVSSv3.1: High ( 7.1 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVE ID: CVE-2026-103009
Problem Type: CWE-639 - Authorization Bypass Through User-Controlled Key