CVE-2024-37286Medium· 5.7▾ SunlitAPM Server vulnerable to Insertion of Sensitive Information into Log File
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.5%
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.
github.com/elastic/apm-server < 8.14.0Upgrade to a patched release:
github.com/elastic/apm-server 8.14.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-68383Medium· 6.5Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
CVE-2026-26933Medium· 5.7Packetbeat does not properly validate an array index in multiple protocol parser components
CVE-2026-26931Medium· 5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
CVE-2024-14047High· 7.2A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users
CVE-2026-78602Medium· 5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126)