{"record":"Elastic Security evidence record","url":"https://nexalign.io/vendors/elastic-security","vendor":{"slug":"elastic-security","name":"Elastic Security","domain":"elastic.co","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-18T10:21:49.516Z","coverage":{"earliest":"2014-07-28T19:00:00.000Z","latest":"2026-07-18T10:21:49.516Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":64,"kindsOfSource":7,"attributedAdvisories":41,"knownExploited":1,"registerEntriesNotAttributable":11,"practitionerThreads":0,"independentItems":3,"vendorPublishedItems":1,"shareFromSourcesTheVendorDoesNotControl":0.95},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":26,"latest":"2026-05-28T19:48:31.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":26,"latest":"2026-07-02T11:35:53.682Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":1,"latest":"2022-03-25T00:00:00.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":5,"latest":"2026-07-18T10:21:49.516Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":2,"latest":"2026-06-21T16:20:46.000Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2026-01-23T14:36:18.000Z"},{"source":"The vendor's own documentation","operator":"Vendor website, indexed by nexalign","classification":"vendor-controlled","items":3,"latest":"2026-07-03T22:48:25.711Z"}],"advisories":{"shown":6,"total":41,"truncated":true,"fullList":"https://nexalign.io/vendors/elastic-security/advisories","items":[{"id":"CVE-2014-3120","description":"Elasticsearch Remote Code Execution Vulnerability","severity":"critical","cvss":8.1,"knownExploited":true,"date":"2022-03-25T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2014-3120","https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5879"]},{"id":"WID-SEC-2026-2180","description":"Affected products: Open Source Elasticsearch","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2026-07-02T11:35:53.682Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2180"]},{"id":"CVE-2026-49095","description":"Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation.","severity":"high","cvss":7.2,"knownExploited":false,"date":"2026-05-28T19:48:31.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33033"]},{"id":"WID-SEC-2026-0099","description":"Affected products: Open Source Elasticsearch","severity":"medium","cvss":7.5,"knownExploited":false,"date":"2026-01-14T08:00:53.409Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0099"]},{"id":"WID-SEC-2025-2896","description":"Affected products: Open Source Elasticsearch","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2025-12-19T11:44:57.991Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2896"]},{"id":"WID-SEC-2025-2841","description":"Affected products: Open Source Elasticsearch","severity":"medium","cvss":6.8,"knownExploited":false,"date":"2025-12-16T08:45:32.576Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2841"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Elastic Security Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/elastic/product/elastic-security","date":null},{"title":"Top Elastic Security Competitors & Alternatives 2025 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/elastic/product/elastic-security/alternatives","date":null},{"title":"Elastic Security Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/elastic/product/elastic-security","date":null}]},"vendorPublished":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Elastic — The Search AI Company","url":"https://www.elastic.co/","date":"2026-07-03T22:48:25.711Z"}]},"openQuestions":["A further 11 register entries mention Elastic Security without naming a product of Elastic Security as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Elastic Security was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}