Known Vulnerabilities for Enterprise Search by Elastic
Listed below are 4 of the newest known vulnerabilities associated with "Enterprise Search" by "Elastic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61218 json | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search I... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-61060 json | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search I... | Not Provided | 2026-07-21 | 2026-07-24 |
| CVE-2026-57230 json | OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise edition... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-34260 json | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-20298 json | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0,... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-20296 json | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0,... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-20259 json | In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-9152 json | A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index op... | Not Provided | 2026-05-21 | 2026-05-21 |
| CVE-2021-47974 json | VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services ... | Not Provided | 2026-05-16 | 2026-05-18 |
| CVE-2021-37940 json | An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search ... | 6.8 - MEDIUM | 2021-12-07 | 2021-12-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Enterprise Search | 7.9.0 | |||
| Application | Elastic | Enterprise Search | 7.8.1 | |||
| Application | Elastic | Enterprise Search | 7.8.0 | |||
| Application | Elastic | Enterprise Search | 7.7.1 | |||
| Application | Elastic | Enterprise Search | 7.7.0 | |||
| Application | Elastic | Enterprise Search | - |