Elastic has 34 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 28 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (10) and CWE-863 (4). Most affected products: Elasticsearch (12), Kibana (12), github.com/elastic/apm-server (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 28 prev 1
Weakness classes
Products
- Elasticsearch 12
- Kibana 12
- github.com/elastic/apm-server 2
- github.com/elastic/beats/v7 2
- elastic_cloud_on_kubernetes 1
- endpoint_security 1
Worst active — by depth score
CVE-2026-78583High· 8.1Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153)45CVE-2026-72672High· 7.7The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting us…42CVE-2026-72670High· 7.7A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy42CVE-2026-72669High· 7.6The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership42CVE-2026-4498High· 7.7Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122)42
Elastic vulnerabilities
CVEs affecting Elastic, newest first. Open any entry for full detail, references, and exploit status.
34 CVEsRSS
CVE-2026-26931Medium· 5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
CVE-2025-68383Medium· 6.5Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File