Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Elastic — Vulnerabilities & Security Advisories 309

Browse all 309 CVE security advisories affecting Elastic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elastic operates as a search and analytics engine, primarily powering the ELK Stack for log management and data visualization. With 223 recorded Common Vulnerabilities and Exposures, the platform has historically been susceptible to critical flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from improper input validation and authentication bypasses within its Java-based architecture. Notable incidents involve unauthorized access to sensitive data through exposed APIs, highlighting risks associated with default configurations. The sheer volume of CVEs suggests persistent challenges in securing complex distributed systems. While the software remains a cornerstone for enterprise search, its extensive attack surface requires rigorous patching and strict access controls to mitigate the high probability of exploitation by threat actors targeting its widespread deployment infrastructure.

Found 153 results / 309 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-49096 Uncaught Exception in Kibana Cases Leading to Denial of Service — Kibana CWE-248 4.3 Medium 2026-08-13
CVE-2026-72632 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys — Kibana CWE-203 7.1 High 2026-08-13
CVE-2026-72631 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys — Kibana CWE-269 6.5 Medium 2026-08-13
CVE-2026-72630 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation — Kibana CWE-863 7.1 High 2026-08-13
CVE-2026-72629 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models — Kibana CWE-639 7.1 High 2026-08-13
CVE-2026-72643 Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents — Kibana CWE-863 7.1 High 2026-08-13
CVE-2026-72655 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification — Kibana CWE-915 4.3 Medium 2026-08-13
CVE-2026-72653 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service — Kibana CWE-770 6.5 Medium 2026-08-13
CVE-2026-72651 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service — Kibana CWE-770 6.5 Medium 2026-08-13
CVE-2026-72650 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure — Kibana CWE-639 4.3 Medium 2026-08-13
CVE-2026-72663 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service — Kibana CWE-407 6.5 Medium 2026-08-13
CVE-2026-72661 Missing Authorization in Kibana Leading to Information Disclosure — Kibana CWE-862 6.5 Medium 2026-08-13
CVE-2026-72660 Uncaught Exception in Kibana Leading to Denial of Service — Kibana CWE-248 6.5 Medium 2026-08-13
CVE-2026-72659 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service — Kibana CWE-770 6.5 Medium 2026-08-13
CVE-2026-72658 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation — Kibana CWE-352 7.3 High 2026-08-13
CVE-2026-72667 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service — Kibana CWE-770 6.5 Medium 2026-08-13
CVE-2026-72666 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts — Kibana CWE-639 6.8 Medium 2026-08-13
CVE-2026-72665 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions — Kibana CWE-862 8.1 High 2026-08-13
CVE-2026-72664 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions — Kibana CWE-862 6.5 Medium 2026-08-13
CVE-2026-72677 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources — Kibana CWE-23 7.3 High 2026-08-13
CVE-2026-72675 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification — Kibana CWE-862 7.1 High 2026-08-13
CVE-2026-72674 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service — Kibana CWE-770 6.5 Medium 2026-08-13
CVE-2026-72673 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations — Kibana CWE-863 5.4 Medium 2026-08-13
CVE-2026-72672 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data — Kibana CWE-863 7.7 High 2026-08-13
CVE-2026-72671 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments — Kibana CWE-862 4.3 Medium 2026-08-13
CVE-2026-72670 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials — Kibana CWE-200 7.7 High 2026-08-13
CVE-2026-72669 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering — Kibana CWE-862 7.6 High 2026-08-13
CVE-2026-72681 Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure — Kibana CWE-862 6.5 Medium 2026-08-13
CVE-2026-72680 Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification — Kibana CWE-639 6.5 Medium 2026-08-13
CVE-2026-49089 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service — Kibana CWE-770 6.5 Medium 2026-08-13

This page lists every published CVE security advisory associated with Elastic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.