{"id":"CVE-2025-37729","title":"Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted strin…","summary":"Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted strin…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-1336"],"vendor":"elastic","product":"elastic_cloud_enterprise","affected":["elastic_cloud_enterprise >= 2.5.0, < 3.8.2","elastic_cloud_enterprise >= 4.0.0, < 4.0.2"],"patched":["elastic_cloud_enterprise 4.0.2"],"published":"2025-10-13","updated":"2026-10-01","sourceUpdated":"2026-10-01T16:10:00.257","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-37729","references":[{"url":"https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-2-and-4-0-2-security-update-esa-2025-21/382641","label":"security@elastic.co"}],"tags":["nvd"],"epss":0.00665,"epssPercentile":0.49934,"ingestedAt":"2026-10-01T18:55:42.297Z","slug":"CVE-2025-37729","body":"## Overview\n\nImproper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.\n\n## Affected\n\n- `elastic_cloud_enterprise >= 2.5.0, < 3.8.2`\n- `elastic_cloud_enterprise >= 4.0.0, < 4.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `elastic_cloud_enterprise 4.0.2`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}