Endpoint security (EDR and XDR)
Elastic Security advisories: every record the registers tie to its products
In one line
41 advisories are attributed to Elastic Security products in this record, covering June 2017 to July 2026, and 1 of them appears in the CISA catalogue of known exploited vulnerabilities. A further 11 register entries mention Elastic Security without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.
Attributed
41
tied to a named product
Known exploited
1
in the CISA catalogue
Rated critical
2
by the register
Last checked
Jul 18, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Elastic Security, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
11 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
38 of the 41 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2014-3120criticalCVSS 8.1Known exploitedMar 25, 2022
Elasticsearch Remote Code Execution Vulnerability
- WID-SEC-2026-2180mediumCVSS 6.5Jul 02, 2026
Affected products: Open Source Elasticsearch
- CVE-2026-49095highCVSS 7.2May 28, 2026
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation.
- WID-SEC-2026-0099mediumCVSS 7.5Jan 14, 2026
Affected products: Open Source Elasticsearch
- WID-SEC-2025-2896mediumCVSS 6.5Dec 19, 2025
Affected products: Open Source Elasticsearch
- WID-SEC-2025-2841mediumCVSS 6.8Dec 16, 2025
Affected products: Open Source Elasticsearch
- CVE-2025-37736highCVSS 8.8Nov 07, 2025
Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed.
- WID-SEC-2025-2217mediumCVSS 5.7Oct 13, 2025
Affected products: Open Source Elasticsearch
- WID-SEC-2025-2235mediumCVSS 6.5Oct 09, 2025
Affected products: Open Source Elasticsearch, Juniper Junos Space
- WID-SEC-2025-2234highCVSS 8.6Oct 09, 2025
Affected products: Open Source Elasticsearch, Juniper Junos Space
- WID-SEC-2025-2233mediumCVSS 6.3Oct 09, 2025
Affected products: Red Hat Enterprise Linux, Open Source Elasticsearch, Juniper Junos Space
- WID-SEC-2025-0923mediumCVSS 6.5May 02, 2025
Affected products: Open Source Elasticsearch
- CVE-2023-46669mediumCVSS 6.2May 01, 2025
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the…
- WID-SEC-2025-0742mediumCVSS 5.3Apr 09, 2025
Affected products: Open Source Elasticsearch
- WID-SEC-2025-0133mediumCVSS 6.5Jan 21, 2025
Affected products: Open Source Elasticsearch
- WID-SEC-2024-3718mediumCVSS 6.5Dec 18, 2024
Affected products: Open Source Elasticsearch
- CVE-2024-12539mediumCVSS 6.0Dec 17, 2024
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get…
- WID-SEC-2024-0759lowCVSS 4.3Nov 28, 2024
Affected products: Open Source Elasticsearch
- WID-SEC-2024-0742mediumCVSS 4.9Nov 12, 2024
Affected products: Open Source Elasticsearch
- WID-SEC-2024-3184mediumCVSS 5.1Oct 16, 2024
Affected products: Red Hat Enterprise Linux, Open Source Elasticsearch, Open Source Kibana, SolarWinds Platform
- CVE-2024-37288criticalCVSS 9.9Sep 09, 2024
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload.
- WID-SEC-2024-1739mediumCVSS 4.9Aug 01, 2024
Affected products: Open Source Elasticsearch
- CVE-2024-23445mediumCVSS 6.5Jun 12, 2024
It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-clust…
- WID-SEC-2024-1314mediumCVSS 4.9Jun 07, 2024
Affected products: Open Source Elasticsearch
- WID-SEC-2024-1296mediumCVSS 6.5Jun 06, 2024
Affected products: Open Source Elasticsearch
- WID-SEC-2023-2387mediumCVSS 6.5Feb 09, 2024
Affected products: Open Source Elasticsearch
- CVE-2024-23446mediumCVSS 6.5Feb 07, 2024
An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the…
- WID-SEC-2023-3126mediumCVSS 5.2Dec 13, 2023
Affected products: Open Source Elasticsearch
- CVE-2023-46675highCVSS 8.0Dec 13, 2023
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug level logging is enabled in Kibana.
- WID-SEC-2023-2986mediumCVSS 6.5Nov 22, 2023
Affected products: Open Source Elasticsearch
- CVE-2023-46666mediumCVSS 5.3Oct 26, 2023
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector.
- WID-SEC-2023-1602mediumCVSS 7.5Oct 04, 2023
Affected products: Open Source Elasticsearch, Hitachi Ops Center
- WID-SEC-2023-2433mediumCVSS 7.5Sep 25, 2023
Affected products: Open Source Elasticsearch
- WID-SEC-2023-2276lowCVSS 4.1Sep 07, 2023
Affected products: Open Source Elasticsearch
- WID-SEC-2023-1134highCVSS 9.9May 03, 2023
Affected products: Open Source Elasticsearch, Open Source Filebeat
- CVE-2022-38777highCVSS 7.8Feb 08, 2023
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem…
- CVE-2022-38775highCVSS 7.8Jan 24, 2023
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem…
- CVE-2022-38774highCVSS 7.8Jan 24, 2023
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of…
- CVE-2017-8445Aug 18, 2017
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1.
- CVE-2017-8442Jul 07, 2017
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and…
- CVE-2016-10364Jun 16, 2017
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests…
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 26 | May 28, 2026 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 26 | Jul 02, 2026 |
| Known Exploited Vulnerabilities catalogue | CISA, United States | 1 | Mar 25, 2022 |
The entry counts here are the raw register totals for Elastic Security, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Elastic Security have?
41 advisories in this record are tied by a register to a product of Elastic Security. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Elastic Security vulnerabilities being actively exploited?
1 of the 41 records here appears in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.
Why does this page show fewer CVEs for Elastic Security than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 11 register entries name Elastic Security without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Elastic Security advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Elastic Security is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full Elastic Security record, including sources and open questions
