Elastic Cloud Enterprise

Vendor:

First CVE: Sep 19, 2018 · Active for 7 years

9
Total CVEs
More Total CVEs than 88% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Elastic Cloud Enterprise over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2018
7 years ago
Most Recent CVE
Nov 7, 2025
263 days ago

CVE Severity & Scoring

Elastic Cloud Enterprise9 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High3 (33.3%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High1 (11.1%)
None4 (44.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that
Nov 7, 20258.830NONO
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive infor
Oct 13, 20257.229NONO
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys tha
Jun 28, 20249.825NONO
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemo
Oct 26, 20237.523NONO
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption
Sep 19, 20187.523NONO
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such
Aug 25, 20226.522NONO
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monito
Sep 28, 20225.320NONO
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless expl
Sep 19, 20185.920NONO
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access
Sep 19, 20185.319NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Elastic Cloud Enterprise

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.6.017.51.2%00