Medium severity4.6NVD Advisory· Published Oct 26, 2023· Updated Jun 17, 2026
CVE-2023-46668
CVE-2023-46668
Description
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
2- www.elastic.co/community/securitynvdMitigationVendor Advisory
- discuss.elastic.co/t/endpoint-v8-10-4-security-update/345203nvdRelease Notes
News mentions
0No linked articles in our index yet.