← Vulnerability feed

Vulnerability record · CVE-2018-3829 · published 19 September 2018

CVE-2018-3829: Elastic cloud enterprise improper authorization vulnerability

Elastic · Elastic Cloud Enterprise

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.

5.3 CVSS 3.1 Medium EPSS 0.90% · top 42.1% CWE-285 · Improper authorizationCWE-290 · Authentication bypass by spoofing
5.3CVSS 3.1 base score, v2 3.5
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-3829 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-37282Elastic cloud enterprise improper authorization vulnerabilityIt was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently …EPSS 0.60%8.8CVE-2025-37736Elastic cloud enterprise incorrect authorization vulnerabilityImproper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be…EPSS 0.38%7.5CVE-2023-31418Elasticsearch uncontrolled resource consumption vulnerabilityAn issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch…EPSS 2.1%7.5CVE-2018-3828Elastic cloud enterprise sensitive information in log file vulnerabilityElastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception condit…EPSS 0.60%7.2CVE-2025-37729Elastic cloud enterprise vulnerabilityImproper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin acce…EPSS 0.66%6.5CVE-2022-23715Elastic cloud enterprise sensitive information in log file vulnerabilityA flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystor…EPSS 0.80%5.9CVE-2018-3825Elastic cloud enterprise insecure default initialization vulnerabilityIn Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elas…EPSS 0.65%5.3CVE-2022-23716Elastic cloud enterprise sensitive information in log file vulnerabilityA flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment…EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2018-3829), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.