AZL-106715

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106715.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106715
Upstream
  • CVE-2026-102407
Published
2026-10-06T20:17:12Z
Modified
2026-10-07T14:17:13Z
Summary
CVE-2026-102407 affecting package rubygem-elasticsearch 8.9.0-1
Details

Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which they were not otherwise authorized, potentially injecting data into it or affecting its ability to be searched normally. This issue does not allow an attacker to read the contents of a data stream they do not otherwise have access to.

References

Affected packages

Azure Linux:3 / rubygem-elasticsearch

Package

Name
rubygem-elasticsearch
Purl
pkg:rpm/azure-linux/rubygem-elasticsearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.9.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106715.json"