Elastic
First CVE: Jun 5, 2017Active for: 9 years
264
CVEs Published
More CVEs Published than 82% of tracked CNAs
26.4
Avg CVEs / Year
More Avg CVEs / Year than 74% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Elastic as a CNA, 93.9% affect products that Elastic develops as a vendor.
93.9%
Self-reported: 248Third-party: 16
Of all the CVEs published that affect products developed by Elastic, 93.9% are self-published by Elastic as a CNA.
93.9%
Self-published: 248Published by other CNAs: 16
Trends Over Time
The number and severity of CVEs published by Elastic over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2017
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by Elastic as a CNA, regardless of affected vendor or product.
264 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7609CRITICAL Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a reques | Mar 25, 2019 | 10.0 | 98 | YES | YES |
CVE-2021-22145MEDIUM A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submi | Jul 21, 2021 | 6.5 | 86 | NO | YES |
CVE-2018-17246CRITICAL Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that | Dec 20, 2018 | 9.8 | 83 | NO | YES |
CVE-2023-31419HIGH A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service. | Oct 26, 2023 | 7.5 | 57 | NO | NO |
CVE-2021-22146HIGH All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no perm | Jul 21, 2021 | 7.5 | 50 | NO | YES |
CVE-2020-7012HIGH Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana inde | Jun 3, 2020 | 8.8 | 40 | NO | YES |
CVE-2025-25014CRITICAL A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. | May 6, 2025 | 9.8 | 39 | NO | NO |
CVE-2026-49091HIGH Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input | Jul 1, 2026 | 8.0 | 37 | NO | NO |
CVE-2026-56150HIGH Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specia | Jul 1, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-33466CRITICAL Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal | Apr 8, 2026 | 9.8 | 33 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA264 CVEs
64%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (6.4%)
Network236 (89.4%)
Unknown0 (0.0%)
Physical1 (0.4%)
Adjacent Network10 (3.8%)
Attack Complexity
Low238 (90.2%)
High26 (9.8%)
Unknown0 (0.0%)
User Interaction
None220 (83.3%)
Unknown0 (0.0%)
Required44 (16.7%)
Privileges Required
Low153 (58.0%)
High17 (6.4%)
None94 (35.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (264 CVEs).
CISA KEV
1 CVE
0.4% of CVEs· 83rd percentile
Metasploit
3 CVEs
1.1% of CVEs· 87th percentile
Nuclei
3 CVEs
1.1% of CVEs· 81st percentile
ExploitDB
2 CVEs
0.8% of CVEs· 80th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Elastic as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Elastic as a CNA — matched by CVE ID, not by organization name.