Elastic develops a narrowly focused but deeply embedded suite of search, analytics, and data-pipeline products—Elasticsearch, Kibana, Logstash, and related platform components—that have become foundational infrastructure across enterprise logging, security monitoring, and observability stacks. The vendor's vulnerability volume is substantial and concentrated in a relatively small product portfolio, reflecting both the central role these products occupy in critical workflows and the breadth of their deployment across industries. Vulnerabilities affecting Elastic skew toward a meaningful share of serious outcomes and recur through weakness classes centered on input-handling and information-disclosure flaws—cross-site scripting in Kibana's web interface, sensitive data exposure in logs and API responses, and resource-consumption vulnerabilities—that are endemic to data-intensive platforms serving as centralized repositories for operational and security data. Defenders should treat Elastic component updates as high-priority for internet-exposed instances and log aggregation pipelines, and should review configurations for overly permissive access and unredacted sensitive content in indexed data. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elastic over time
Of all the CVEs published by Elastic as a CNA, 93.9% affect products that Elastic develops as a vendor.
Of all the CVEs published that affect products developed by Elastic, 93.9% are self-published by Elastic as a CNA.
Signals from CVEs in this vendor scope (264 CVEs).
264 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1427CRITICAL The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell comm | Feb 17, 2015 | 9.8 | 99 | YES | YES |
CVE-2019-7609CRITICAL Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a reques | Mar 25, 2019 | 10.0 | 98 | YES | YES |
CVE-2014-3120HIGH The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source pa | Jul 28, 2014 | 8.1 | 97 | YES | YES |
CVE-2021-22145MEDIUM A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submi | Jul 21, 2021 | 6.5 | 86 | NO | YES |
CVE-2018-17246CRITICAL Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that | Dec 20, 2018 | 9.8 | 83 | NO | YES |
CVE-2023-31419HIGH A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service. | Oct 26, 2023 | 7.5 | 57 | NO | NO |
CVE-2021-22146HIGH All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no perm | Jul 21, 2021 | 7.5 | 50 | NO | YES |
CVE-2020-7012HIGH Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana inde | Jun 3, 2020 | 8.8 | 40 | NO | YES |
CVE-2025-25014CRITICAL A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. | May 6, 2025 | 9.8 | 39 | NO | NO |
CVE-2026-49091HIGH Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input | Jul 1, 2026 | 8.0 | 37 | NO | NO |
Signals from CVEs in this vendor scope (264 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elastic.
Media articles that mention a CVE ID that affects a product developed by Elastic — matched by CVE ID, not by vendor name.