Elastic Security Updates – 07 July 2026

Elastic has released security updates to address several vulnerabilities affecting multiple Elastic products.

The addressed vulnerabilities could allow the attacker to conduct denial-of-service attacks, manipulate data, obtain sensitive information, gain elevated privileges, perform server-side request forgery (SSRF), and cross-site scripting (XSS) attacks, leading to unauthorized access to the affected systems.

Sample of addressed vulnerabilities:

1. Kibana Improper Output Neutralization for Logs Vulnerability (CVE-2026- 49091):

  • CVSS: 8.0
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Data Manipulation

2. Kibana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-42398):

  • CVSS: 7.7
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Server-Side Request Forgery

The affected products:

  • Elasticsearch.
  • Kibana.
  • Fleet Server.
  • Elastic Defend.
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Elastic Security Advisory

References