---
id: CVE-2026-102407
title: >-
  Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized
  data stream modification via Accessing Functionality Not Properly Constrained
  by ACLs (CAPEC-1)
summary: >-
  Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized
  data stream modification via Accessing Functionality Not Properly Constrained
  by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a
  single r…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-863
vendor: Elastic
product: Elasticsearch
affected:
  - Elasticsearch >= 7.17.5 <= 7.17.29
  - Elasticsearch >= 8.2.2 <= 8.19.18
  - Elasticsearch >= 9.0.0 <= 9.3.7
  - Elasticsearch >= 9.4.0 <= 9.4.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:12.647'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102407'
references:
  - url: >-
      https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-188/390861
    label: security@elastic.co
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T19:56:21.979941Z'
ingestedAt: '2026-10-06T20:16:42.471Z'
---

## Overview

Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which they were not otherwise authorized, potentially injecting data into it or affecting its ability to be searched normally. This issue does not allow an attacker to read the contents of a data stream they do not otherwise have access to.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
