Known Vulnerabilities for Elasticsearch by Anynines
Listed below are 1 of the newest known vulnerabilities associated with "Elasticsearch" by "Anynines".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49095 json | Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An a... | Not Provided | 2026-05-28 | 2026-05-30 |
| CVE-2026-45009 json | phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordi... | Not Provided | 2026-05-15 | 2026-05-28 |
| CVE-2026-42401 json | Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with... | Not Provided | 2026-05-28 | 2026-05-29 |
| CVE-2026-41018 json | The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pass... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-40970 json | When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification w... | Not Provided | 2026-04-27 | 2026-04-27 |
| CVE-2026-31215 json | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch servi... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-5417 json | A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the fil... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-4498 json | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data b... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2025-61872 json | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query str... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2019-3800 json | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the use... | 7.8 - HIGH | 2019-08-05 | 2019-10-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Anynines | Elasticsearch | 2.1.2 | |||
| Application | Anynines | Elasticsearch | 2.1.1 | |||
| Application | Anynines | Elasticsearch | 2.1.0 | |||
| Application | Anynines | Elasticsearch | 2.0.2 | |||
| Application | Anynines | Elasticsearch | 2.0.1 | |||
| Application | Anynines | Elasticsearch | 1.0.0 | |||
| Application | Anynines | Elasticsearch | 0.9.4 | |||
| Application | Anynines | Elasticsearch | 0.9.3 | |||
| Application | Anynines | Elasticsearch | 0.9.2 | |||
| Application | Anynines | Elasticsearch | 0.9.1 | |||
| Application | Anynines | Elasticsearch | 0.9.0 | |||
| Application | Anynines | Elasticsearch | - |