Vulnerabilities in Elastic

352 results
Vexday analysis

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2025-68388MEDIUMAllocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEEPSS 0.4%CVE-2024-52974MEDIUMAn issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A succeEPSS 0.4%CVE-2026-72676MEDIUMImproper Control of Generation of Code in Fleet Server Leading to Code InjectionEPSS 0.4%CVE-2024-52972MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2024-43708MEDIUMAn allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of iEPSS 0.4%CVE-2025-68390MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.4%CVE-2026-78602MEDIUMImproper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File DisclosureEPSS 0.4%CVE-2025-37736HIGHElastic Cloud Enterprise Improper AuthorizationEPSS 0.4%CVE-2024-52973MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2024-37279MEDIUMKibana Broken Access Control issueEPSS 0.4%CVE-2026-72654MEDIUMExecution with Unnecessary Privileges in Kibana Leading to Information DisclosureEPSS 0.4%CVE-2026-72660MEDIUMUncaught Exception in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72683MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72686MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2023-46666MEDIUMElastic Sharepoint Online Python Connector Improper Access ControlEPSS 0.4%CVE-2024-23447MEDIUMElastic Network Drive Connector Improper Access ControlEPSS 0.4%CVE-2023-31416MEDIUMElastic Cloud on Kubernetes (ECK) secret token configuration issueEPSS 0.4%CVE-2025-25013MEDIUMElastic Defend Insertion of Sensitive Information into Log FilesEPSS 0.4%CVE-2026-63137HIGHIncorrect Authorization in Kibana Leading to Privilege EscalationEPSS 0.4%CVE-2023-46668MEDIUMElastic Endpoint Insertion of Sensitive Information into Log FileEPSS 0.3%