Elastic Elastic Elastic

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Elastic product.

RSS Feeds for Elastic security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Elastic products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Elastic Sorted by Most Security Vulnerabilities since 2018

Elastic Kibana197 vulnerabilities

Elasticsearch82 vulnerabilities

Elastic Cloud Enterprise9 vulnerabilities

Elastic Logstash7 vulnerabilities

Elastic Enterprise Search5 vulnerabilities

Elastic Apm Server5 vulnerabilities

Elastic Endpoint Security3 vulnerabilities

Elastic Agent3 vulnerabilities

Elastic Endgame2 vulnerabilities

Known Exploited Elastic Vulnerabilities

The following Elastic vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2015-1427 Exploit Probability: 99.9%
March 25, 2022
Elasticsearch Remote Code Execution Vulnerability Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2014-3120 Exploit Probability: 88.6%
March 25, 2022
Kibana Arbitrary Code Execution Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
CVE-2019-7609 Exploit Probability: 95.3%
January 10, 2022

Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 163 vulnerabilities in Elastic with an average score of 6.2 out of ten. Last year, in 2025 Elastic had 41 security vulnerabilities published. That is, 122 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.53




Year Vulnerabilities Average Score
2026 163 6.19
2025 41 6.72
2024 19 6.44
2023 31 6.95
2022 11 5.66
2021 21 5.76
2020 13 6.10
2019 14 8.38
2018 20 7.11

It may take a day or so for new Elastic vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Elastic Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-94408 Sep 26, 2026
Elasticsearch CVE-2026-94408: Uncontrolled Res. Cons. (CWE-400) DoS Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Elasticsearch
CVE-2026-94397 Sep 26, 2026
Elasticsearch Uncontrolled Resource Cons. (CWE400) Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Elasticsearch
CVE-2026-94396 Sep 26, 2026
Elasticsearch Uncontrolled Resource Consumption DoS Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Elasticsearch
CVE-2026-94400 Sep 26, 2026
Kibana Uncontrolled Resource Consumption: Potential DoS via Excessive Allocation Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
Kibana
CVE-2026-94399 Sep 26, 2026
Elasticsearch DoS via Uncontrolled Resource Consumption (CWE-400) Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Elasticsearch
CVE-2026-94398 Sep 26, 2026
Elasticsearch Uncontrolled Resource Consumption (CWE-400) CAPEC-130 DoS Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Elasticsearch
CVE-2026-82300 Sep 26, 2026
Elasticsearch DoS via Uncontrolled Resource Consumption (CWE-400) Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Elasticsearch
CVE-2026-82294 Sep 26, 2026
Elasticsearch DoS via Uncontrolled Resource Consumption Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Elasticsearch
CVE-2026-78582 Sep 26, 2026
Kibana Missing Auth: Unauthorized Deletion of Synthetics Monitors Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.
Kibana
CVE-2026-72662 Sep 26, 2026
Kibana Authorization Bypass via User-Controlled Key (CWE-639) Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.
Kibana
CVE-2026-72668 Sep 26, 2026
Kibana Agent Builder Confused Deputy Privilege Escalation Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster.
Kibana
CVE-2026-82302 Sep 03, 2026
Kibana Unauthorized Config Mod via Incorrect Authorization (CWE-863) Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Kibana
CVE-2026-82299 Sep 03, 2026
Kibana Incorrect Auth (CWE-863) Enables Info Disclosure Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Kibana
CVE-2026-82298 Sep 03, 2026
Kibana Incorrect Authorization Leading to DoS via Misconfigured Access Control Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Kibana
CVE-2026-78596 Sep 03, 2026
Kibana Missing Auth: Unauthorized Data Mod via Space Migration Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.
Kibana
CVE-2026-78595 Sep 03, 2026
Missing Auth in Kibana Fleet: Read-Only Agent Credentials Leak Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces.
Kibana
CVE-2026-78593 Sep 03, 2026
Kibana Cribl RCE via Insufficient Validation of Config Field An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions.
Kibana
CVE-2026-78583 Sep 03, 2026
CVE-2026-78583: Kibana Privilege Escalation via Unvalidated Agent Credentials Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.
Kibana
CVE-2026-82293 Sep 02, 2026
Kibana ML Feature - Incorrect Auth. Enables Unauthorized Resource Consumption Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach.
Kibana
CVE-2026-78588 Sep 02, 2026
Filebeat HTTP ingestion endpoint allows unchecked memory allocation Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.
CVE-2026-78587 Sep 02, 2026
Fleet Server Auth Bypass Enables Agent Upload Denial of Service Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.
CVE-2026-78586 Sep 02, 2026
Kibana Unbounded Memory Allocation Leads to DoS by Low-Priv Auth User Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.
Kibana
CVE-2026-78584 Sep 02, 2026
Kibana Osquery LiveQuery Disclosure via Identifier Existence Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
Kibana
CVE-2026-78591 Sep 02, 2026
Kibana Fleet Path Traversal leads to unauthorized deletion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Kibana
CVE-2026-78590 Sep 02, 2026
Elastic Kibana Fleet Path Traversal Deletion Vulnerability Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.
Kibana
CVE-2026-78599 Sep 02, 2026
Kibana Fleet Path Traversal Violation Leads to Deletion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Kibana
CVE-2026-78598 Sep 02, 2026
Kibana ML Job Auth Escalation: CrossSpace Data Exposure Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
Kibana
CVE-2026-78594 Sep 02, 2026
APM Server Denial via Highly Compressed Source Map (CWE409/CAPEC130) Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Apm Server
CVE-2026-78604 Sep 02, 2026
Elastic Agent: Incorrect Perm. Assignment Causing Local Priv Escalation Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
Elastic Agent
CVE-2026-78602 Sep 02, 2026
Elastic Maps Server Path Traversal can expose file contents Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.
CVE-2026-78601 Sep 02, 2026
Kibana Entity Store Auth Bypass Exposes Data Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output.
Kibana
CVE-2026-78600 Sep 02, 2026
ECK Incomplete Cleanup Enables LowPrivileged Privilege Abuse Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
CVE-2026-78609 Sep 02, 2026
Incorrect Auth in ECK Enables Namespace-Scoped Metadata Spoofing Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
CVE-2026-63138 Sep 01, 2026
Kibana NoSQLi Enables Unauthorized Data Disclosure Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
Kibana
CVE-2026-78597 Sep 01, 2026
Kibana Entity Store Missing Auth: Unauthorized API Key Creation Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires.
Kibana
CVE-2026-78592 Sep 01, 2026
Elastic's Kibana Path Traversal (CWE-22) Enables Unauthorized Resource Deletion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.
Kibana
CVE-2026-78606 Sep 01, 2026
Kibana Unauthorized Access to Elastic AI Assistant KB via ACL flaw Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.
Kibana
CVE-2026-78603 Sep 01, 2026
Kibana RBAC Bypass Enables Fleet Metadata Disclosure Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
Kibana
CVE-2026-78607 Sep 01, 2026
Elasticsearch Custom Inference Service Missing Auth => Info Disclosure Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
Elasticsearch
CVE-2026-78608 Sep 01, 2026
Kibana Missing Auth Allows APM Credentials Leak Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM server credentials that should be restricted to users holding APM or Fleet administrative privileges.
Kibana
CVE-2026-78605 Sep 01, 2026
Elasticsearch HTTP Request Smuggling: Info Disclosure Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.
Elasticsearch
CVE-2026-72654 Sep 01, 2026
Kibana ML Privilege Abuse (CWE-250) Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.
Kibana
CVE-2026-72633 Sep 01, 2026
Kibana Entity Analytics Authorization Bypass Enables ACL Skip Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
Kibana
CVE-2026-72641 Sep 01, 2026
Kibana Unauthorized Mod via Entity Store Maintainer Tasks (CWE-863) Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
Kibana
CVE-2026-72628 Sep 01, 2026
Kibana DoS via CVE-2026-72628 Zip Bomb Memory Exhaustion Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.
Kibana
CVE-2026-72644 Sep 01, 2026
Kibana DoS via Unhandled Exception in Observability AI Assistant Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.
Kibana
CVE-2026-72649 Sep 01, 2026
Elasticsearch ML: Remote Code Exec via Untrusted Deserialized Trained Model Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.
Elasticsearch
CVE-2026-72682 Sep 01, 2026
Kibana Unbounded Memory DoS via Low-Privilege Agent Builder (CWE-770) Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.
Kibana
CVE-2026-63137 Sep 01, 2026
Kibana Privilege Escalation via Workflow Edit RBAC Bypass (CVE-2026-63137) Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
Kibana
CVE-2026-72652 Sep 01, 2026
Kibana AuthDoS via Unbounded Resource Allocation Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
Kibana
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.