Elasticsearch maintains a focused portfolio of data-analytics and log-management products—including Elasticsearch, Kibana, Logstash, and Packetbeat—that are widely deployed in security operations and observability pipelines. The recurring vulnerability surface centers on web-application and input-handling weaknesses such as cross-site scripting, path traversal, improper array validation, and exposure of sensitive data, characteristic of platforms that ingest and surface untrusted log and event streams. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elasticsearch over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5531MEDIUM Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls. | Aug 17, 2015 | 5.0 | 84 | NO | YES |
CVE-2015-3337MEDIUM Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecifi | May 1, 2015 | 4.3 | 45 | NO | YES |
CVE-2026-26932HIGH Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can sen | Feb 26, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-0529MEDIUM Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network t | Jan 14, 2026 | 6.5 | 25 | NO | NO |
CVE-2020-7017MEDIUM In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could ob | Jul 27, 2020 | 6.7 | 24 | NO | NO |
CVE-2017-11480HIGH Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able | Dec 8, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-14730HIGH The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to | Sep 25, 2017 | 7.8 | 24 | NO | NO |
CVE-2026-26933MEDIUM Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker wi | Mar 19, 2026 | 5.7 | 22 | NO | NO |
CVE-2025-68381MEDIUM Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause signi | Dec 18, 2025 | 6.5 | 22 | NO | NO |
CVE-2015-4165HIGH The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, a | Aug 9, 2017 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elasticsearch.
Media articles that mention a CVE ID that affects a product developed by Elasticsearch — matched by CVE ID, not by vendor name.