VYPR

Vendor CVEs

Elastic

All CVEs

371 total · sorted by risk
  • CVE-2021-22135MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level…

  • CVE-2020-7015MedJun 3, 2020
    risk 0.35cvss 5.4epss 0.01

    Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users…

  • CVE-2019-7619MedOct 30, 2019
    risk 0.35cvss 5.3epss 0.02

    Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

  • CVE-2018-17244MedDec 20, 2018
    risk 0.35cvss 6.5epss 0.01

    Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being…

  • CVE-2018-3829MedSep 19, 2018
    risk 0.35cvss 5.3epss 0.01

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an…

  • CVE-2018-3823MedSep 19, 2018
    risk 0.35cvss 5.4epss 0.01

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from…

  • CVE-2017-8446MedAug 18, 2017
    risk 0.35cvss 5.3epss 0.01

    The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly…

  • CVE-2026-78602MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the…

  • CVE-2026-78591MedSep 2, 2026
    risk 0.34cvss 6.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a…

  • CVE-2026-56144MedJul 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause…

  • CVE-2026-56152MedJul 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not…

  • CVE-2026-49093MedMay 28, 2026
    risk 0.34cvss 6.3epss 0.00

    Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to…

  • CVE-2026-33458MedApr 8, 2026
    risk 0.34cvss 6.3epss 0.00

    Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive…

  • CVE-2023-49921MedJul 26, 2024
    risk 0.34cvss 5.2epss 0.00

    An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by…

  • CVE-2024-23447MedFeb 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications…

  • CVE-2023-31416MedOct 26, 2023
    risk 0.34cvss 5.3epss 0.00

    Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

  • CVE-2023-46666MedOct 26, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all…

  • CVE-2022-23716MedSep 28, 2022
    risk 0.34cvss 5.3epss 0.01

    A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.

  • CVE-2023-46669MedMay 1, 2025
    risk 0.33cvss 6.2epss 0.00

    Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that…

  • CVE-2019-7608MedMar 25, 2019
    risk 0.33cvss 6.1epss 0.01

    Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2016-1000220MedJun 16, 2017
    risk 0.33cvss 6.1epss 0.01

    Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.

  • CVE-2026-26936MedFeb 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).

  • CVE-2024-23443MedJun 19, 2024
    risk 0.32cvss 4.9epss 0.02

    A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

  • CVE-2024-37280MedJun 13, 2024
    risk 0.32cvss 4.9epss 0.01

    A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and…

  • CVE-2024-23450MedMar 27, 2024
    risk 0.32cvss 4.9epss 0.01

    A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

  • CVE-2020-7021MedFeb 10, 2021
    risk 0.32cvss 4.9epss 0.01

    Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow…

  • CVE-2026-78605MedSep 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses…

  • CVE-2026-33467MedApr 28, 2026
    risk 0.31cvss 5.9epss 0.00

    Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity…

  • CVE-2021-22132MedJan 14, 2021
    risk 0.31cvss 4.8epss 0.01

    Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers…

  • CVE-2020-7016MedJul 27, 2020
    risk 0.31cvss 4.8epss 0.01

    Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

  • CVE-2019-7614MedJul 30, 2019
    risk 0.31cvss 5.9epss 0.01

    A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from…

  • CVE-2015-5619MedAug 9, 2017
    risk 0.31cvss 5.9epss 0.01

    Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

  • CVE-2026-26933MedMar 19, 2026
    risk 0.30cvss 5.7epss 0.00

    Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network…

  • CVE-2025-37727MedOct 10, 2025
    risk 0.30cvss 5.7epss 0.00

    Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

  • CVE-2024-11994MedMay 1, 2025
    risk 0.30cvss 5.7epss 0.00

    APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs.

  • CVE-2024-37286MedAug 3, 2024
    risk 0.30cvss 5.7epss 0.00

    APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the…

  • CVE-2024-23448MedFeb 7, 2024
    risk 0.30cvss 5.7epss 0.01

    An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted…

  • CVE-2023-46668MedOct 26, 2023
    risk 0.30cvss 4.6epss 0.00

    If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed…

  • CVE-2026-78601MedSep 2, 2026
    risk 0.29cvss 5.5epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly…

  • CVE-2024-23451MedMar 27, 2024
    risk 0.29cvss 4.4epss 0.00

    Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote…

  • CVE-2026-82298MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-78596MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana…

  • CVE-2026-78595MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space…

  • CVE-2026-78593MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being…

  • CVE-2026-82293MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their…

  • CVE-2026-78598MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single…

  • CVE-2026-78607MedSep 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their…

  • CVE-2026-72641MedSep 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the…

  • CVE-2026-72671MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create…

  • CVE-2026-72650MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve…

Page 6 of 8