FAIL › dossier
Elastic
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 50%
Elastic has demonstrated a recurring pattern of high-severity vulnerabilities, particularly RCE flaws, across its core products. This history necessitates careful consideration of their security posture and potential risks when integrated into DIB/CMMC environments.
PROFILE
CategorySoftwareWhat they doElastic is a company that develops and sells search, observability, and security solutions. Their products include Elasticsearch, Kibana, and Logstash.
SECURITY POSTURE
Elastic has a history of high-severity remote code execution (RCE) vulnerabilities across multiple components, indicating a potential weakness in secure coding practices. Remediation efforts include security awareness training and improved security posture processes.
Notable failures
- CVE-2015-1427 (RCE)
- CVE-2014-3120 (RCE)
- CVE-2019-7609 (RCE)
- CVE-2026-33466 (Path Traversal)
Patterns: repeated RCE vulnerabilities; improper limitation of directory access
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-01-10 | CVE-2019-7609 | high | Elastic Kibana's Timelion visualizer contained an arbitrary code execution flaw that was actively exploited in the wild. |
| 2022-03-25 | CVE-2015-1427 | high | Elasticsearch's Groovy scripting engine allowed remote attackers to bypass sandbox protections and execute arbitrary shell commands. |
| 2022-03-25 | CVE-2014-3120 | high | Elasticsearch's dynamic scripting feature allowed remote attackers to execute arbitrary MVEL and Java code, a flaw listed in CISA's KEV catalog. |
| 2026-04-08 | CVE-2026-33466 | high | CVE-2026-33466: Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash |
FEDRAMP CATALOG PRODUCTS · 1
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Elastic Cloud | Authorized | Moderate |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:19:07.379125+00:00