Known Vulnerabilities for Elasticsearch by Elastic
Listed below are 10 of the newest known vulnerabilities associated with "Elasticsearch" by "Elastic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41018 json | The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pass... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-40970 json | When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification w... | Not Provided | 2026-04-27 | 2026-04-27 |
| CVE-2026-31215 json | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch servi... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-5417 json | A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the fil... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-4498 json | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data b... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2025-61872 json | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query str... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2023-46673 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-22 | 2023-11-30 |
| CVE-2023-31419 json | A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a St... | 7.5 - HIGH | 2023-10-26 | 2024-02-01 |
| CVE-2023-31418 json | An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user coul... | 7.5 - HIGH | 2023-10-26 | 2023-11-30 |
| CVE-2023-31417 json | Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that ... | 4.4 - MEDIUM | 2023-10-26 | 2024-01-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Elasticsearch | 7.9.2 | |||
| Application | Elastic | Elasticsearch | 7.9.0 | |||
| Application | Elastic | Elasticsearch | 7.8.1 | |||
| Application | Elastic | Elasticsearch | 7.8.0 | |||
| Application | Elastic | Elasticsearch | 7.7.1 | |||
| Application | Elastic | Elasticsearch | 7.7.0 | |||
| Application | Elastic | Elasticsearch | 7.6.2 | |||
| Application | Elastic | Elasticsearch | 7.6.1 | |||
| Application | Elastic | Elasticsearch | 7.6.0 | |||
| Application | Elastic | Elasticsearch | 7.5.2 | |||
| Application | Elastic | Elasticsearch | 7.5.1 | |||
| Application | Elastic | Elasticsearch | 7.5.0 | |||
| Application | Elastic | Elasticsearch | 7.4.2 | |||
| Application | Elastic | Elasticsearch | 7.4.1 | |||
| Application | Elastic | Elasticsearch | 7.4.0 | |||
| Application | Elastic | Elasticsearch | 7.3.2 | |||
| Application | Elastic | Elasticsearch | 7.3.1 | |||
| Application | Elastic | Elasticsearch | 7.3.0 | |||
| Application | Elastic | Elasticsearch | 7.2.1 | |||
| Application | Elastic | Elasticsearch | 7.2.0 |