CVE Tools

Elastic Cloud Enterprise

11 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Elastic Cloud Enterprise, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Elastic Cloud Enterprise CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Elastic Cloud Enterprise CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical19%
  • High545%
  • Medium545%

Latest CVEs

The 11 most recently published vulnerabilities affecting Elastic Cloud Enterprise.

  1. CVE-2025-37736Elastic Cloud Enterprise Improper Authorization8.8
  2. CVE-2025-37729Elastic Cloud Enterprise (ECE) Improper Neutralization of Special Elements Used in a Template Engine9.1
  3. CVE-2024-37282It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated p...8.1
  4. CVE-2023-31418Elasticsearch uncontrolled resource consumption7.5
  5. CVE-2022-23716A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.5.3
  6. CVE-2022-23715A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log ...6.5
  7. CVE-2021-22146All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and i...7.5
  8. CVE-2018-3829In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous ...5.3
  9. CVE-2018-3828Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords,...7.5
  10. CVE-2018-3825In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritte...5.9
  11. CVE-2017-8444The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the cli...5.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store