Known Vulnerabilities for products from Elastic
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Elastic".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72683 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-72672 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-72666 json | Not Provided | 2026-08-13 | 2026-08-14 | |
| CVE-2026-72665 json | Not Provided | 2026-08-13 | 2026-08-14 | |
| CVE-2026-72664 json | Not Provided | 2026-08-13 | 2026-08-14 | |
| CVE-2026-72661 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-72655 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-72648 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-72640 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-72632 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-63263 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CA... | Not Provided | 2026-07-22 | 2026-08-03 |
| CVE-2026-63262 json | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input... | Not Provided | 2026-07-22 | 2026-08-03 |
| CVE-2026-63261 json | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A l... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63260 json | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An ... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63259 json | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied ide... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63145 json | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification recor... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63144 json | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submit... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63143 json | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A ... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63142 json | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting fea... | Not Provided | 2026-07-21 | 2026-08-03 |
| CVE-2026-63141 json | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and s... | Not Provided | 2026-07-21 | 2026-08-06 |
Known software with vulnerabilities from Elastic
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Elastic | Apm-agent-ruby | - |
| Application | Elastic | Apm Agent | - |
| Application | Elastic | Elasticsearch | 0.10.0 |
| Application | Elastic | Elasticsearch X-pack | 5.0.0 |
| Application | Elastic | Elastic App Search | 7.7.0 |
| Application | Elastic | Elastic Cloud Enterprise | 1.0.0 |
| Application | Elastic | Elastic Cloud On Kubernetes | 1.1.0 |
| Application | Elastic | Enterprise Search | - |
| Application | Elastic | Kibana | 0.10.0 |
| Application | Elastic | Kibana Reporting | 2.4.0 |
| Application | Elastic | Kibana X-pack | 5.0.0 |
| Application | Elastic | Logstash | 1.0.0 |
| Application | Elastic | Logstash X-pack | 5.6.0 |
| Application | Elastic | Winlogbeat | 1.1.0 |
| Application | Elastic | X-pack | 5.0.0 |