vciy

CVEs we hold for Elastic

Records whose assigning authority named Elastic as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-82302Incorrect Authorization in Kibana Leading to Unauthorized Configuration ModificationElastic Kibana
CVE-2026-82299Incorrect Authorization in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-82298Incorrect Authorization in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-82293Incorrect Authorization in Kibana Leading to Unauthorized Resource ConsumptionElastic Kibana
CVE-2026-78609Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of DataElastic Eck Operator
CVE-2026-78608Missing Authorization in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-78607Missing Authorization in Elasticsearch Leading to Information DisclosureElastic Elasticsearch
CVE-2026-78606Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of DataElastic Kibana
CVE-2026-78605Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information…Elastic Elasticsearch
CVE-2026-78604Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEMElastic Agent
CVE-2026-78603Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment MetadataElastic Kibana
CVE-2026-78602Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File…Elastic Maps Server
CVE-2026-78601Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data ExposureElastic Kibana
CVE-2026-78600Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential RetentionElastic Eck Operator
CVE-2026-78599Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal ResourcesElastic Kibana
CVE-2026-78598Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job DataElastic Kibana
CVE-2026-78597Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key CreationElastic Kibana
CVE-2026-78596Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write OperationsElastic Kibana
CVE-2026-78595Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data DisclosureElastic Kibana
CVE-2026-78594Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of ServiceElastic Apm Server
CVE-2026-78593Improper Control of Generation of Code in Kibana Leading to Privilege EscalationElastic Kibana
CVE-2026-78592Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged…Elastic Kibana
CVE-2026-78591Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized…Elastic Kibana
CVE-2026-78590Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged…Elastic Kibana
CVE-2026-78588Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of ServiceElastic Filebeat
CVE-2026-78587Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload OperationsElastic Fleet Server
CVE-2026-78586Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-78584Observable Response Discrepancy in Kibana Leading to Cross-Space Information DisclosureElastic Kibana
CVE-2026-78583Incorrect Authorization in Kibana Leading to Privilege EscalationElastic Kibana
CVE-2026-78581Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in KibanaElastic Kibana
CVE-2026-72687Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72686Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72685Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72684Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72683Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72682Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72681Missing Authorization in Kibana Leading to Privilege Escalation and Information DisclosureElastic Kibana
CVE-2026-72680Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data ModificationElastic Kibana
CVE-2026-72679Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72678Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72677Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other ResourcesElastic Kibana
CVE-2026-72676Improper Control of Generation of Code in Fleet Server Leading to Code InjectionElastic Fleet Server
CVE-2026-72675Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data…Elastic Kibana
CVE-2026-72674Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72673Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private LocationsElastic Kibana
CVE-2026-72672Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event DataElastic Kibana
CVE-2026-72671Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space AssignmentsElastic Kibana
CVE-2026-72670Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy CredentialsElastic Kibana
CVE-2026-72669Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data TamperingElastic Kibana
CVE-2026-72667Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72666Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed HostsElastic Kibana
CVE-2026-72665Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response ActionsElastic Kibana
CVE-2026-72664Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response ActionsElastic Kibana
CVE-2026-72663Inefficient Algorithmic Complexity in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72661Missing Authorization in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-72660Uncaught Exception in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72659Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72658Cross-Site Request Forgery in Kibana Leading to Privilege EscalationElastic Kibana
CVE-2026-72657Authorization Bypass Through User-Controlled Key in Fleet Server Leading to Information DisclosureElastic Fleet Server
CVE-2026-72656Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72655Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data…Elastic Kibana
CVE-2026-72654Execution with Unnecessary Privileges in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-72653Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72652Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72651Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72650Authorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-72649Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code ExecutionElastic Elasticsearch
CVE-2026-72648Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to…Elastic Eck Operator
CVE-2026-72647Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72645Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72644Uncaught Exception in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-72643Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private AgentsElastic Kibana
CVE-2026-72642Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference ProcessElastic Elasticsearch
CVE-2026-72641Incorrect Authorization in Kibana Leading to Unauthorized Modification of DataElastic Kibana
CVE-2026-72640Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret DisclosureElastic Eck Operator
CVE-2026-72639Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72638Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72636Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-72633Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege MonitoringElastic Kibana
CVE-2026-72632Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API KeysElastic Kibana
CVE-2026-72631Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API KeysElastic Kibana
CVE-2026-72630Incorrect Authorization in Kibana Fleet Leading to Privilege EscalationElastic Kibana
CVE-2026-72629Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained…Elastic Kibana
CVE-2026-72628Improper Handling of Highly Compressed Data in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-63263Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-63262Missing Authorization in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-63261Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-63260Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-63259Authorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-63145Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity CompromiseElastic Kibana
CVE-2026-63144Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-63143Missing Authorization in Kibana Leading to Unauthorized Information DisclosureElastic Kibana
CVE-2026-63142Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request ForgeryElastic Kibana
CVE-2026-63141Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management FunctionsElastic Kibana
CVE-2026-63140Reachable Assertion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-63139Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-63138Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-63137Incorrect Authorization in Kibana Leading to Privilege EscalationElastic Kibana
CVE-2026-63136Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-56152Incorrect Authorization in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-56151Improper Input Validation in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-56150Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of ServiceElastic Fleet Server
CVE-2026-56149Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-56148Uncontrolled Recursion in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-56147Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case…Elastic Kibana
CVE-2026-56146Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information DisclosureElastic Kibana
CVE-2026-56145Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-56144Incorrect Authorization in Elasticsearch Leading to Information DisclosureElastic Elasticsearch
CVE-2026-56143Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-49096Uncaught Exception in Kibana Cases Leading to Denial of ServiceElastic Kibana
CVE-2026-49095Improper Input Validation in Kibana Fleet Leading to Privilege EscalationElastic Kibana
CVE-2026-49094Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-49093Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessElastic Kibana
CVE-2026-49092Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information ExposureElastic Kibana
CVE-2026-49091Improper Output Neutralization for Logs in Kibana Leading to Log InjectionElastic Kibana
CVE-2026-49090Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceElastic Elasticsearch
CVE-2026-49089Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-49088Insertion of Sensitive Information into Log File in Kibana Leading to Information DisclosureElastic Kibana
CVE-2026-49087Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-4498Execution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC…Elastic Kibana
CVE-2026-42401Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HTML InjectionElastic Kibana
CVE-2026-42400Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-42399Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-42398Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessElastic Kibana
CVE-2026-42397Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-33467Improper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity BypassElastic Package Registry
CVE-2026-33466Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File WriteElastic Logstash
CVE-2026-33465Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-33464Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-33463Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File AccessElastic Kibana
CVE-2026-33462Path Traversal in Kibana Leading to Unauthorized Deletion of User AccountsElastic Kibana
CVE-2026-33461Incorrect Authorization in Kibana Fleet Leading to Information DisclosureElastic Kibana
CVE-2026-33460Incorrect Authorization in Kibana Fleet Leading to Information DisclosureElastic Kibana
CVE-2026-33459Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-33458Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information DisclosureElastic Kibana
CVE-2026-26940Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-26939Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action ConfigurationElastic Kibana
CVE-2026-26938Improper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading to Server-Side…Elastic Kibana
CVE-2026-26937Uncontrolled Resource Consumption in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-26936Inefficient Regular Expression Complexity in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-26935Improper Input Validation in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-26934Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceElastic Kibana
CVE-2026-26933Improper Validation of Array Index in Packetbeat Leading to Denial of ServiceElastic Packetbeat
CVE-2026-26932Improper Validation of Array Index in Packetbeat Leading to Denial of ServiceElastic Packetbeat
CVE-2026-26931Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of ServiceElastic Metricbeat
CVE-2026-0543Improper Input Validation in Kibana Email Connector Leading to Excessive AllocationElastic Kibana
CVE-2026-0532External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini ConnectorElastic Kibana
CVE-2026-0531Allocation of Resources Without Limits or Throttling in Kibana FleetElastic Kibana
CVE-2026-0530Allocation of Resources Without Limits or Throttling in Kibana Leading to Excessive AllocationElastic Kibana
CVE-2026-0529Improper Validation of Array Index in Packetbeat Leading to Overflow BuffersElastic Packetbeat
CVE-2026-0528Improper Input Validation in Metricbeat Leading to Denial of ServiceElastic Metricbeat
CVE-2025-68422Kibana Improper AuthorizationElastic Kibana
CVE-2025-68390Elasticsearch Allocation of Resources Without Limits or ThrottlingElastic Elasticsearch
CVE-2025-68389Kibana Allocation of Resources Without Limits or ThrottlingElastic Kibana
CVE-2025-68388no title heldElastic Packetbeat
CVE-2025-68387Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Elastic Kibana
CVE-2025-68386Kibana Improper AuthorizationElastic Kibana
CVE-2025-68385Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Elastic Kibana
CVE-2025-68384Elasticsearch Allocation of Resources Without Limits or ThrottlingElastic Elasticsearch
CVE-2025-68383Filebeat Improper Validation of Specified Index, Position, or Offset in InputElastic Filebeat
CVE-2025-68382Packetbeat Out-of-bounds ReadElastic Packetbeat
CVE-2025-68381Packetbeat Improper Bounds CheckElastic Packetbeat
CVE-2025-66525WordPress Elastic Email Sender plugin <= 1.2.20 - Broken Access Control vulnerabilityElastic Email Sender
CVE-2025-37736Elastic Cloud Enterprise Improper AuthorizationElastic Cloud Enterprise (ECE)
CVE-2025-37735no title heldElastic Kibana
CVE-2025-37734Kibana Origin Validation ErrorElastic Kibana
CVE-2025-37732Kibana Cross-site Scripting via the Integration Package Upload FunctionalityElastic Kibana
CVE-2025-37731Elasticsearch Improper AuthenticationElastic Elasticsearch
CVE-2025-37730Logstash Improper Certificate Validation in TCP outputElastic Logstash
CVE-2025-37729Elastic Cloud Enterprise (ECE) Improper Neutralization of Special Elements Used in a Template EngineElastic Cloud Enterprise (ECE)
CVE-2025-37728Kibana Insufficiently Protected Credentials in the CrowdStrike ConnectorElastic Kibana
CVE-2025-37727Elasticsearch Insertion of sensitive information in log fileElastic Elasticsearch
CVE-2025-28985WordPress Elastic Email Subscribe Form plugin <= 1.2.2 - Broken Access Control VulnerabilityElastic Email Subscribe Form
CVE-2025-25018Kibana Stored Cross-Site Scripting (XSS)Elastic Kibana
CVE-2025-25017Kibana Stored Cross-Site Scripting (XSS)Elastic Kibana
CVE-2025-25016Kibana Unrestricted Upload of FileElastic Kibana
CVE-2025-25015Kibana arbitrary code execution via prototype pollutionElastic Kibana
CVE-2025-25014Kibana arbitrary code execution via prototype pollutionElastic Kibana
CVE-2025-25013Elastic Defend Insertion of Sensitive Information into Log FilesElastic Defend
CVE-2025-25012Kibana Open RedirectElastic Kibana
CVE-2025-25011Beats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerElastic Beats
CVE-2025-25010Kibana privilege escalation via reporting_user roleElastic Kibana
CVE-2025-25009Kibana Cross-Site Scripting (XSS)Elastic Kibana
CVE-2025-0712APM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows…Elastic APM Server
CVE-2024-52981no title heldElastic Elasticsearch
CVE-2024-52980Elasticsearch Uncontrolled Resource Consumption vulnerabilityElastic Elasticsearch
CVE-2024-52979Elasticsearch Uncontrolled Resource Consumption vulnerabilityElastic Elasticsearch
CVE-2024-52976Elastic Agent Inclusion of Functionality from Untrusted Control SphereElastic Agent
CVE-2024-52975Fleet Server sensitive information exposure via logsElastic Fleet Server
CVE-2024-52974no title heldElastic Kibana
CVE-2024-52973Kibana allocation of resources without limits or throttling leads to crashElastic Kibana
CVE-2024-52972Kibana allocation of resources without limits or throttling leads to crashElastic Kibana
CVE-2024-43710Kibana server-side request forgeryElastic Kibana
CVE-2024-43709Elasticsearch allocation of resources without limits or throttling leads to crashElastic Elasticsearch
CVE-2024-43708no title heldElastic Kibana
CVE-2024-43707Kibana exposure of sensitive information to an unauthorized actorElastic Kibana
CVE-2024-43706Kibana Improper AuthorizationElastic Kibana
CVE-2024-37288no title heldElastic Kibana
CVE-2024-37287Kibana arbitrary code execution via prototype pollutionElastic Kibana
CVE-2024-37286APM Server Insertion of Sensitive Information into Log FileElastic APM Server

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.