Vulnerabilities in Elastic

352 results
Vexday analysis

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-72633MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege MonitoringEPSS 0.2%CVE-2026-78607MEDIUMMissing Authorization in Elasticsearch Leading to Information DisclosureEPSS 0.2%CVE-2026-26939MEDIUMMissing Authorization in Kibana Leading to Unauthorized Endpoint Response Action ConfigurationEPSS 0.2%CVE-2025-37731MEDIUMElasticsearch Improper AuthenticationEPSS 0.2%CVE-2025-68386MEDIUMKibana Improper AuthorizationEPSS 0.2%CVE-2025-68383MEDIUMFilebeat Improper Validation of Specified Index, Position, or Offset in InputEPSS 0.2%CVE-2026-63141MEDIUMMissing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management FunctionsEPSS 0.2%CVE-2026-78600LOWIncomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential RetentionEPSS 0.2%CVE-2026-26931MEDIUMMemory Allocation with Excessive Size Value in Metricbeat Leading to Denial of ServiceEPSS 0.2%CVE-2025-37732MEDIUMKibana Cross-site Scripting via the Integration Package Upload FunctionalityEPSS 0.2%CVE-2023-46669MEDIUMElastic Agent / Elastic Endpoint Security local API key disclosureEPSS 0.2%CVE-2026-33460MEDIUMIncorrect Authorization in Kibana Fleet Leading to Information DisclosureEPSS 0.2%CVE-2026-78593MEDIUMImproper Control of Generation of Code in Kibana Leading to Privilege EscalationEPSS 0.2%CVE-2026-78603MEDIUMMissing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment MetadataEPSS 0.2%CVE-2026-78597MEDIUMMissing Authorization in Kibana Entity Store Leading to Unauthorized API Key CreationEPSS 0.2%CVE-2025-37730MEDIUMLogstash Improper Certificate Validation in TCP outputEPSS 0.2%CVE-2026-78595MEDIUMMissing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data DisclosureEPSS 0.2%CVE-2026-78596MEDIUMMissing Authorization in Kibana Leading to Unauthorized Cross-Space Write OperationsEPSS 0.2%CVE-2017-8445An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manEPSS 0.2%CVE-2024-37284MEDIUMElastic Defend Improper Handling of Alternate Encoding Leads to CrashEPSS 0.2%