Elastic vendor intelligence
Elastic Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Elastic products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting Elastic products
- In CISA KEV
- 3
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- Elastic KEV with sensor-observed exploitation activity
The catalog gap matters for Elastic exposure
One of the four exploited Elastic CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-quarter of this vendor portfolio.
- 75%
- Covered by CISA
- 25%
- Beyond CISA
- 2
- Product families
Attested Elastic CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-17246
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana... |
Kibana | High | Beyond CISA | 20 May 2025 |
|
CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the... |
Kibana | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2014-3120
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL... |
Elasticsearch | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism... |
Elasticsearch | Confirmed | In CISA | 25 Mar 2022 |
No Elastic CVEs match this search or filter.
Showing 4 of 4 Elastic known exploited vulnerabilities.
Recurring weakness patterns
Access control, external control, and control account for three mapped occurrences across this Elastic KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.