VYPR
Medium severity6.5NVD Advisory· Published Sep 19, 2018· Updated Jun 17, 2026

CVE-2018-3826

CVE-2018-3826

Description

In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Elastic/Elasticsearchllm-fuzzy2 versions
    >=6.0.0-beta1, <=6.2.4+ 1 more
    • (no CPE)range: >=6.0.0-beta1, <=6.2.4
    • (no CPE)range: 6.0.0-beta1 to 6.2.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.