Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Elasticsearch

First CVE: Oct 10, 2014Active for: 12 yearsTotal CVEs: 20
29.7
VTI Score
Low

Elasticsearch maintains a focused portfolio of data-analytics and log-management products—including Elasticsearch, Kibana, Logstash, and Packetbeat—that are widely deployed in security operations and observability pipelines. The recurring vulnerability surface centers on web-application and input-handling weaknesses such as cross-site scripting, path traversal, improper array validation, and exposure of sensitive data, characteristic of platforms that ingest and surface untrusted log and event streams. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Elasticsearch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2014
11 years ago
Most Recent CVE
Mar 19, 2026
127 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-5531MEDIUM
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
Aug 17, 20155.084NOYES
CVE-2015-3337MEDIUM
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecifi
May 1, 20154.345NOYES
CVE-2026-26932HIGH
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can sen
Feb 26, 20267.526NONO
CVE-2026-0529MEDIUM
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network t
Jan 14, 20266.525NONO
CVE-2020-7017MEDIUM
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could ob
Jul 27, 20206.724NONO
CVE-2017-11480HIGH
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able
Dec 8, 20177.524NONO
CVE-2017-14730HIGH
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to
Sep 25, 20177.824NONO
CVE-2026-26933MEDIUM
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker wi
Mar 19, 20265.722NONO
CVE-2025-68381MEDIUM
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause signi
Dec 18, 20256.522NONO
CVE-2015-4165HIGH
The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, a
Aug 9, 20177.521NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
75%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (5.0%)
Network12 (60.0%)
Unknown3 (15.0%)
Physical0 (0.0%)
Adjacent Network4 (20.0%)
Attack Complexity
Low12 (60.0%)
High5 (25.0%)
Unknown3 (15.0%)
User Interaction
None14 (70.0%)
Unknown3 (15.0%)
Required3 (15.0%)
Privileges Required
Low6 (30.0%)
High0 (0.0%)
None11 (55.0%)
Unknown3 (15.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.0% of CVEs· 98th percentile
Nuclei
2 CVEs
10.0% of CVEs· 96th percentile
ExploitDB
2 CVEs
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Elasticsearch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Elasticsearch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Elasticsearch's Products

View all 2 CNAs →

Top CWEs