Information Exposure Vulnerability in Elastic Agent and Elastic Security Endpoint
CVE-2023-46669

6.2MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
1 May 2025

What is CVE-2023-46669?

The vulnerability in Elastic Agent and Elastic Security Endpoint exposes sensitive information to unauthorized local actors, which may compromise confidentiality and enable impersonation of the endpoint within the Elastic Stack. This issue has been recognized by Elastic engineers, and there is currently no indication of exploitation by malicious actors.

Affected Version(s)

Elastic Agent and Elastic Defend 8.0.0 < 8.15.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.