Medium severity6.5NVD Advisory· Published Sep 19, 2018· Updated Jun 17, 2026
CVE-2018-3826
CVE-2018-3826
Description
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2>=6.0.0-beta1, <=6.2.4+ 1 more
- (no CPE)range: >=6.0.0-beta1, <=6.2.4
- (no CPE)range: 6.0.0-beta1 to 6.2.4
Patches
Vulnerability mechanics
References
2- discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777nvdVendor Advisory
- www.elastic.co/community/securitynvdVendor Advisory
News mentions
0No linked articles in our index yet.