Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Elastic

First CVE: Jul 22, 2014Active for: 12 yearsTotal CVEs: 264
50.2
VTI Score
TOP TARGET

Elastic develops a narrowly focused but deeply embedded suite of search, analytics, and data-pipeline products—Elasticsearch, Kibana, Logstash, and related platform components—that have become foundational infrastructure across enterprise logging, security monitoring, and observability stacks. The vendor's vulnerability volume is substantial and concentrated in a relatively small product portfolio, reflecting both the central role these products occupy in critical workflows and the breadth of their deployment across industries. Vulnerabilities affecting Elastic skew toward a meaningful share of serious outcomes and recur through weakness classes centered on input-handling and information-disclosure flaws—cross-site scripting in Kibana's web interface, sensitive data exposure in logs and API responses, and resource-consumption vulnerabilities—that are endemic to data-intensive platforms serving as centralized repositories for operational and security data. Defenders should treat Elastic component updates as high-priority for internet-exposed instances and log aggregation pipelines, and should review configurations for overly permissive access and unredacted sensitive content in indexed data. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
264
Total CVEs
More Total CVEs than 100% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
1.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Elastic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2014
12 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Self-Reporting Analysis

Of all the CVEs published by Elastic as a CNA, 93.9% affect products that Elastic develops as a vendor.

93.9%
Self-reported: 248 (93.9%)
Third-party: 16 (6.1%)

Of all the CVEs published that affect products developed by Elastic, 93.9% are self-published by Elastic as a CNA.

93.9%
Self-published: 248 (93.9%)
Other CNAs: 16 (6.1%)

Products(30 total)

Top CVEs

Signals from CVEs in this vendor scope (264 CVEs).

264 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-1427CRITICAL
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell comm
Feb 17, 20159.899YESYES
CVE-2019-7609CRITICAL
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a reques
Mar 25, 201910.098YESYES
CVE-2014-3120HIGH
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source pa
Jul 28, 20148.197YESYES
CVE-2021-22145MEDIUM
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submi
Jul 21, 20216.586NOYES
CVE-2018-17246CRITICAL
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that
Dec 20, 20189.883NOYES
CVE-2023-31419HIGH
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
Oct 26, 20237.557NONO
CVE-2021-22146HIGH
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no perm
Jul 21, 20217.550NOYES
CVE-2020-7012HIGH
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana inde
Jun 3, 20208.840NOYES
CVE-2025-25014CRITICAL
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
May 6, 20259.839NONO
CVE-2026-49091HIGH
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input
Jul 1, 20268.037NONO
View all 264 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products264 CVEs
62%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (5.7%)
Network239 (90.5%)
Unknown4 (1.5%)
Physical1 (0.4%)
Adjacent Network5 (1.9%)
Attack Complexity
Low237 (89.8%)
High23 (8.7%)
Unknown4 (1.5%)
User Interaction
None215 (81.4%)
Unknown4 (1.5%)
Required45 (17.0%)
Privileges Required
Low147 (55.7%)
High17 (6.4%)
None96 (36.4%)
Unknown4 (1.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (264 CVEs).

CISA KEV
3 CVEs
1.1% of CVEs· 99th percentile
Metasploit
5 CVEs
1.9% of CVEs· 97th percentile
Nuclei
5 CVEs
1.9% of CVEs· 95th percentile
ExploitDB
4 CVEs
1.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Elastic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Elastic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Elastic's Products

View all 3 CNAs →

Top CWEs