Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.
An attacker with administrator privileges in ECE can provide a specially crafted string containing Jinjava expressions (a template engine based on Java). The application processes this string without proper sanitization and evaluates the variables and template directives contained within it. As a result, it is possible to break out of the intended template context and execute unauthorized operations — both reading sensitive data and issuing system commands.
An attacker can exfiltrate sensitive information stored in the ECE environment and execute commands in the application context, which may lead to complete takeover of the attacked system.
Elastic Cloud Enterprise should be updated to version 3.8.2 or 4.0.2 in accordance with security notice ESA-2025-21 available at: https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-2-and-4-0-2-security-update-esa-2025-21/382641. Until the update is applied, access to the ECE administrator account should be restricted to trusted users only and the administrative panel should be secured at the network level.
Elastic Cloud Enterprise (ECE) — versions indicated in vendor references (vulnerability fixed in ECE 3.8.2 and 4.0.2)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HElastic Cloud Enterprise
APPElastic2.5.0 – 3.8.2 (excl.)4.0.0 – 4.0.2 (excl.)
Related vulnerabilities
Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonl...
It was identified that under certain specific preconditions, an API key that was originally created with a spe...
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenti...
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was d...
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key us...