Vulnerabilities in Elastic

352 results
Vexday analysis

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-49095HIGHImproper Input Validation in Kibana Fleet Leading to Privilege EscalationEPSS 0.3%CVE-2024-43710MEDIUMKibana server-side request forgeryEPSS 0.3%CVE-2026-72650MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2022-38775HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%CVE-2022-38777HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%CVE-2026-26938HIGHImproper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading to Server-Side Request Forgery (SSRF)EPSS 0.3%CVE-2026-72632HIGHObservable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API KeysEPSS 0.3%CVE-2025-68385HIGHKibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.3%CVE-2026-78592HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.3%CVE-2021-37942HIGHAPM Java Agent Local Privilege EscalationEPSS 0.2%CVE-2025-68382MEDIUMPacketbeat Out-of-bounds ReadEPSS 0.2%CVE-2024-11994MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.2%CVE-2025-37727MEDIUMElasticsearch Insertion of sensitive information in log fileEPSS 0.2%CVE-2022-38774HIGHAn issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivilegEPSS 0.2%CVE-2023-46674MEDIUMElasticsearch-hadoop Unsafe DeserializationEPSS 0.2%CVE-2023-31417MEDIUMElasticsearch Insertion of sensitive information in audit logsEPSS 0.2%CVE-2026-63263MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.2%CVE-2026-63136MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.2%CVE-2026-63144MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.2%CVE-2026-63140MEDIUMReachable Assertion in Elasticsearch Leading to Denial of ServiceEPSS 0.2%