VYPR

Vendor CVEs

Elastic

All CVEs

330 total · sorted by risk
  • CVE-2023-31421MedOct 26, 2023
    risk 0.38cvss 5.9epss 0.00

    It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the…

  • CVE-2018-17247MedDec 20, 2018
    risk 0.38cvss 5.9epss 0.01

    Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable…

  • CVE-2018-3825MedSep 19, 2018
    risk 0.38cvss 5.9epss 0.01

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can…

  • CVE-2017-8444MedSep 29, 2017
    risk 0.38cvss 5.9epss 0.01

    The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data.

  • CVE-2015-5619MedAug 9, 2017
    risk 0.38cvss 5.9epss 0.01

    Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

  • CVE-2017-8449MedJun 16, 2017
    risk 0.38cvss 5.9epss 0.01

    X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.

  • CVE-2026-26932MedFeb 26, 2026
    risk 0.37cvss 5.7epss 0.00

    Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process.…

  • CVE-2025-37731MedDec 15, 2025
    risk 0.37cvss 6.8epss 0.00

    Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

  • CVE-2023-6687MedDec 12, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Elastic Agent…

  • CVE-2023-49922MedDec 12, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or…

  • CVE-2024-37284MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This leads to an uncaught exception causing Elastic Defend to crash which in turn will prevent it from quarantining the file…

  • CVE-2017-8445MedAug 18, 2017
    risk 0.36cvss 5.5epss 0.00

    An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node using any certificate to join a cluster. The…

  • CVE-2026-72674MedAug 13, 2026
    risk 0.35cvss 6.5epss

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor…

  • CVE-2026-72673MedAug 13, 2026
    risk 0.35cvss 5.4epss

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it…

  • CVE-2026-56146MedJul 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on…

  • CVE-2026-49094MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint.…

  • CVE-2026-42400MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and…

  • CVE-2026-42399MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion…

  • CVE-2026-33459MedApr 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple…

  • CVE-2026-0528MedJan 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset.…

  • CVE-2025-68384MedDec 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

  • CVE-2025-68383MedDec 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a…

  • CVE-2025-37732MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018)…

  • CVE-2025-37728MedOct 7, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which…

  • CVE-2024-52979MedMay 1, 2025
    risk 0.35cvss 6.5epss 0.01

    Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

  • CVE-2024-11390MedMay 1, 2025
    risk 0.35cvss 5.4epss 0.00

    Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.

  • CVE-2024-52980MedApr 8, 2025
    risk 0.35cvss 6.5epss 0.01

    A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster…

  • CVE-2024-12539MedDec 17, 2024
    risk 0.35cvss 6.5epss 0.00

    An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

  • CVE-2024-37283MedAug 12, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.

  • CVE-2021-37936MedNov 18, 2022
    risk 0.35cvss 5.4epss 0.00

    It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML,…

  • CVE-2022-23711MedApr 21, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a…

  • CVE-2022-23707MedFeb 11, 2022
    risk 0.35cvss 5.4epss 0.01

    An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

  • CVE-2021-22137MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the…

  • CVE-2021-22135MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level…

  • CVE-2020-7015MedJun 3, 2020
    risk 0.35cvss 5.4epss 0.01

    Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users…

  • CVE-2019-7619MedOct 30, 2019
    risk 0.35cvss 5.3epss 0.02

    Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

  • CVE-2018-3829MedSep 19, 2018
    risk 0.35cvss 5.3epss 0.01

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an…

  • CVE-2018-3823MedSep 19, 2018
    risk 0.35cvss 5.4epss 0.01

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from…

  • CVE-2017-8446MedAug 18, 2017
    risk 0.35cvss 5.3epss 0.01

    The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly…

  • CVE-2026-56144MedJul 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause…

  • CVE-2026-49093MedMay 28, 2026
    risk 0.34cvss 6.3epss 0.00

    Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to…

  • CVE-2026-33458MedApr 8, 2026
    risk 0.34cvss 6.3epss 0.00

    Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive…

  • CVE-2023-49921MedJul 26, 2024
    risk 0.34cvss 5.2epss 0.00

    An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by…

  • CVE-2024-23447MedFeb 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications…

  • CVE-2023-31416MedOct 26, 2023
    risk 0.34cvss 5.3epss 0.00

    Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

  • CVE-2023-46666MedOct 26, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all…

  • CVE-2022-23716MedSep 28, 2022
    risk 0.34cvss 5.3epss 0.01

    A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.

  • CVE-2023-46669MedMay 1, 2025
    risk 0.33cvss 6.2epss 0.00

    Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that…

  • CVE-2019-7608MedMar 25, 2019
    risk 0.33cvss 6.1epss 0.01

    Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2026-26936MedFeb 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).

Page 5 of 7