Medium severity6.5NVD Advisory· Published Sep 19, 2018· Updated Jun 17, 2026
CVE-2018-3826
CVE-2018-3826
Description
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.2.4
- cpe:2.3:a:elastic:elasticsearch:6.0.0:beta1:*:*:*:*:*:*
- (no CPE)range: >=6.0.0-beta1, <=6.2.4
- (no CPE)range: 6.0.0-beta1 to 6.2.4
Patches
Vulnerability mechanics
References
2- discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777nvdVendor Advisory
- www.elastic.co/community/securitynvdVendor Advisory
News mentions
0No linked articles in our index yet.