Vulnerabilities in Elastic

233 results
Vexday analysis

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2025-37727MEDIUMElasticsearch Insertion of sensitive information in log fileEPSS 0.2%CVE-2024-11994MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.2%CVE-2026-33462MEDIUMPath Traversal in Kibana Leading to Unauthorized Deletion of User AccountsEPSS 0.2%CVE-2022-23714A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which EPSS 0.2%CVE-2025-25009HIGHKibana Cross-Site Scripting (XSS)EPSS 0.2%CVE-2025-25018HIGHKibana Stored Cross-Site Scripting (XSS)EPSS 0.2%CVE-2021-37941A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an applicaEPSS 0.2%CVE-2024-23444MEDIUMElasticsearch elasticsearch-certutil csr fails to encrypt private keyEPSS 0.2%CVE-2025-68385HIGHKibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.2%CVE-2025-68382MEDIUMPacketbeat Out-of-bounds ReadEPSS 0.2%CVE-2026-49093MEDIUMServer-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessEPSS 0.2%CVE-2025-37734MEDIUMKibana Origin Validation ErrorEPSS 0.2%CVE-2026-0529MEDIUMImproper Validation of Array Index in Packetbeat Leading to Overflow BuffersEPSS 0.2%CVE-2025-68422MEDIUMKibana Improper AuthorizationEPSS 0.2%CVE-2023-31413MEDIUMFilebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization hEPSS 0.2%CVE-2025-68387MEDIUMKibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.2%CVE-2026-26931MEDIUMMemory Allocation with Excessive Size Value in Metricbeat Leading to Denial of ServiceEPSS 0.2%CVE-2026-26939MEDIUMMissing Authorization in Kibana Leading to Unauthorized Endpoint Response Action ConfigurationEPSS 0.2%CVE-2026-33460MEDIUMIncorrect Authorization in Kibana Fleet Leading to Information DisclosureEPSS 0.2%CVE-2025-68383MEDIUMFilebeat Improper Validation of Specified Index, Position, or Offset in InputEPSS 0.2%