Known vulnerabilities in Elastic Defend
Vendor:
Elastic Stack
Software:
Elastic Defend
Software CPE:
cpe:2.3:a:elastic_stack:elastic_defend:*:*:*:*:*:*:*:*
Website:
https://www.elastic.co/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.7
Breakdown by Severity Chart
9.5.1
9.4.5
8.19.20
9.5.0
8.19.19
9.4.4
9.3.8
8.19.18
9.4.3
9.3.7
8.19.17
9.3.6
9.4.2
9.3.5
8.19.16
9.4.1
9.4.0
8.19.15
9.3.4
9.3.3
9.2.8
8.19.14
9.3.2
9.2.7
8.19.13
9.3.1
9.3.0
9.2.6
9.2.5
8.19.12
8.19.11
9.1.10
9.2.4
8.19.10
8.19.9
9.2.3
9.1.9
9.2.2
9.1.8
8.19.8
9.2.1
9.1.7
8.19.7
8.19.6
8.19.5
8.19.4
8.19.3
8.19.2
8.19.1
8.19.0
8.18.8
8.18.7
8.18.6
8.18.5
8.18.4
8.18.3
8.18.2
8.18.1
8.18.0
8.17.10
8.17.9
8.17.8
8.17.7
8.17.6
9.2.0
9.1.6
9.1.5
9.1.4
9.1.3
9.1.2
9.1.1
9.1.0
9.0.8
9.0.7
9.0.6
9.0.5
9.0.4
9.0.3
9.0.2
9.0.1
8.17.5
8.17.4
8.16.6
8.16.5
8.17.3
8.17.2
8.16.4
8.16.3
8.17.1
8.17.0
8.16.2
8.16.1
8.16.0
8.15.5
8.15.4
8.15.3
8.15.2
8.15.1
8.15.0
8.14.3
8.14.2
8.14.1
8.14.0
8.13.4
8.13.3
8.13.2
8.13.1
8.13.0
8.12.2
8.12.1
8.12.0
8.11.4
8.11.3
8.11.2
8.11.1
8.11.0
8.10.4
8.10.3
8.10.2
8.10.1
8.10.0
8.9.2
8.9.1
8.9.0
8.8.2
8.8.1
8.8.0
8.7.1
8.7.0
8.6.2
8.6.1
8.6.0
8.5.3
8.5.2
8.5.1
8.5.0
8.4.3
8.4.2
8.4.1
8.4.0
8.3.3
8.3.2
8.3.1
8.3.0
8.2.3
8.2.2
8.2.1
8.2.0
8.1.3
8.1.2
8.1.1
8.1.0
8.0.1
8.0.0
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU136673 - Incorrect Authorization CVE-2026-56152 |
CWE-863 | Low | 8.19.13, 9.2.7, 9.3.2 | 02.07.2026 |
SB2026070210 |
||
| #VU118163 - Improper preservation of permissions CVE-2025-37735 |
CWE-281 | Low | 8.19.6, 9.1.6 | 06.11.2025 |
SB2025110642 |
||
| #VU107233 - Exposure of sensitive information to an unauthorized actor CVE-2025-25013 |
CWE-200 | Medium | 8.17.3 | 08.04.2025 |
SB2025040892 |
||
| #VU103110 - Uncaught Exception CVE-2024-37284 |
CWE-248 | Medium | 8.13.3 | 21.01.2025 |
SB2025012118 |