Skip to main content

Vendor/product archive

elastic / elastic_cloud_enterprise CVEs

Beta · best-effort

9 CVEs tagged to elastic / elastic_cloud_enterprise1 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-37736

Published Nov 7, 2025

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs tha…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-37729

Published Oct 13, 2025

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive info…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-37282

Published Jun 28, 2024

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys th…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23716

Published Sep 28, 2022

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monit…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23715

Published Aug 25, 2022

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3829

Published Sep 19, 2018

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with acces…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3828

Published Sep 19, 2018

Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryptio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3825

Published Sep 19, 2018

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless exp…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1