VendorsElasticelastic_cloud_enterpriseany version
Vulnerabilities

Elastic Elastic Cloud Enterprise any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-37282
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.
Published 2024-06-28 · Analyzed
9.8EPSS 0.006
CVE-2025-37729
Elastic Cloud Enterprise (ECE) Improper Neutralization of Special Elements Used in a Template Engine
Published 2025-10-13 · Analyzed
9.1EPSS 0.007
CVE-2025-37736
Elastic Cloud Enterprise Improper Authorization
Published 2025-11-07 · Analyzed
8.8EPSS 0.004
CVE-2023-31418
Elasticsearch uncontrolled resource consumption
Published 2023-10-26 · Modified
7.5EPSS 0.021
CVE-2018-3828
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An attacker with access to the logging cluster may obtain leaked credentials and perform authenticated actions using these credentials.
Published 2018-09-19 · Modified
7.5EPSS 0.006
CVE-2022-23715
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystore
Published 2022-08-25 · Modified
6.5EPSS 0.008
CVE-2018-3825
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.
Published 2018-09-19 · Modified
5.9EPSS 0.007
CVE-2018-3829
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.
Published 2018-09-19 · Modified
5.3EPSS 0.009
CVE-2022-23716
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.
Published 2022-09-28 · Modified
5.3EPSS 0.006