Vulnerabilities in Elastic

352 results
Vexday analysis

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-78606MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of DataEPSS 0.1%CVE-2026-78598MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job DataEPSS 0.1%CVE-2026-42401MEDIUMImproper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HTML InjectionEPSS 0.1%CVE-2025-25011HIGHBeats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2026-33467MEDIUMImproper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity BypassEPSS 0.1%CVE-2026-72658HIGHCross-Site Request Forgery in Kibana Leading to Privilege EscalationEPSS 0.1%CVE-2025-0712HIGHAPM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2025-37735HIGHImproper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the DefenEPSS 0.1%CVE-2026-78581MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in KibanaEPSS 0.1%CVE-2024-14047HIGHImproper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to Arbitrary File Write and Denial of ServiceEPSS 0.1%CVE-2026-78604HIGHIncorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEMEPSS 0.1%CVE-2026-78609MEDIUMIncorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of DataEPSS 0.1%