← CVE Tracker
9.1CRITICAL

CVE-2025-37729 — Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE)…

Elastic · Elastic Cloud Enterprise · Published 13 Oct 2025 · Modified 1 Oct 2026

Description

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.

References

What to do
  1. Check whether Elastic Cloud Enterprise is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-37729