VulnSea

elastic has 23 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 17 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 9. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-863 (4). Most affected products: kibana (8), elasticsearch (5), github.com/elastic/apm-server (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
17 prev 1

Products

  • kibana 8
  • elasticsearch 5
  • github.com/elastic/apm-server 2
  • github.com/elastic/beats/v7 2
  • elastic_cloud_on_kubernetes 1
  • endpoint_security 1
23
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

elastic vulnerabilities

CVEs affecting elastic, newest first. Open any entry for full detail, references, and exploit status.

23 CVEsRSS

CVE-2026-78583High· 8.1
2w ago

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153)

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used…

Twilightelastic · kibanaEPSS 0.22%via NVD
CVE-2026-78602Medium· 5.3
2w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over …

Sunlitelastic · maps_serverEPSS 0.38%via NVD
CVE-2024-14047High· 7.2
3w ago

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesyst…

Twilightelastic · winlogbeatEPSS 0.11%via NVD
CVE-2026-72676Medium· 6.5
1mo ago

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242)

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration wi…

Sunlitelastic · kibanaEPSS 0.39%via NVD
CVE-2026-72672High· 7.7
1mo ago

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting us…

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting us…

Twilightelastic · kibanaEPSS 0.27%via NVD
CVE-2026-72671Medium· 4.3
1mo ago

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytic…

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytic…

Sunlitelastic · kibanaEPSS 0.20%via NVD
CVE-2026-72670High· 7.7
1mo ago

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly …

Twilightelastic · kibanaEPSS 0.34%via NVD
CVE-2026-72669High· 7.6
1mo ago

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read ac…

Twilightelastic · kibanaEPSS 0.23%via NVD
CVE-2026-72657Medium· 6.5
1mo ago

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77)

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-sup…

Sunlitelastic · fleet_serverEPSS 0.28%via NVD
CVE-2026-72656Medium· 6.5
1mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a spec…

Sunlitelastic · elasticsearchEPSS 0.30%via NVD
CVE-2026-72655Medium· 4.3
1mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who h…

Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who h…

Sunlitelastic · kibanaEPSS 0.22%via NVD
CVE-2026-72648Medium· 6.5
1mo ago

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37)

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server r…

Sunlitelastic · elastic_cloud_on_kubernetesEPSS 0.31%via NVD
CVE-2026-63140Medium· 6.5
2mo ago

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153)

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to b…

Sunlitelastic · elasticsearchEPSS 0.24%via NVD
CVE-2026-63136Medium· 6.5
2mo ago

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhau…

Sunlitelastic · elasticsearchEPSS 0.24%via NVD
CVE-2026-56145Medium· 6.5
2mo ago

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they co…

Sunlitelastic · elasticsearchEPSS 0.33%via NVD
CVE-2026-56144Medium· 5.3
2mo ago

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorize…

Sunlitelastic · elasticsearchEPSS 0.23%via NVD
CVE-2026-56152Medium· 5.3
2mo ago

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1)

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access …

Sunlitelastic · endpoint_securityEPSS 0.30%via NVD
CVE-2026-4498High· 7.7
5mo ago

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122)

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana…

Twilightelastic · kibanaEPSS 0.30%via NVD
CVE-2026-26933Medium· 5.7
6mo ago

Packetbeat does not properly validate an array index in multiple protocol parser components

Packetbeat does not properly validate an array index in multiple protocol parser components

Sunlitelastic · github.com/elastic/beats/v7EPSS 0.24%via OSV
CVE-2026-26931Medium· 5.7
6mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Sunlitelastic · metricbeatEPSS 0.18%via NVD
CVE-2025-68383Medium· 6.5
9mo ago

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

Sunlitelastic · github.com/elastic/beats/v7EPSS 0.19%via OSV
CVE-2024-37286Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

Sunlitelastic · github.com/elastic/apm-serverEPSS 0.49%via OSV
CVE-2024-23448Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

Sunlitelastic · github.com/elastic/apm-serverEPSS 0.67%via OSV
elastic vulnerabilities (CVEs) · VulnSea