Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
History

Wed, 01 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elastic Agent
Elastic endpoint Security
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
Vendors & Products Elastic
Elastic elastic Agent
Elastic endpoint Security

Thu, 01 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 May 2025 13:15:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
Title Elastic Agent / Elastic Endpoint Security local API key disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2025-05-01T12:59:49.101Z

Updated: 2025-05-01T15:33:08.751Z

Reserved: 2023-10-24T17:28:32.185Z

Link: CVE-2023-46669

cve-icon Vulnrichment

Updated: 2025-05-01T14:51:51.851Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-01T13:15:49.000

Modified: 2025-10-01T19:31:08.700

Link: CVE-2023-46669

cve-icon Redhat

No data.