Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is:





post:/platform/configuration/security/service-accounts
delete:/platform/configuration/security/service-accounts/{user_id}
patch:/platform/configuration/security/service-accounts/{user_id}
post:/platform/configuration/security/service-accounts/{user_id}/keys
delete:/platform/configuration/security/service-accounts/{user_id}/keys/{api_key_id}
patch:/user
post:/users
post:/users/auth/keys
delete:/users/auth/keys
delete:/users/auth/keys/_all
delete:/users/auth/keys/{api_key_id}
delete:/users/{user_id}/auth/keys
delete:/users/{user_id}/auth/keys/{api_key_id}
delete:/users/{user_name}
patch:/users/{user_name}

Project Subscriptions

Vendors Products
Elastic Subscribe
Elastic Cloud Enterprise Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:elastic_cloud_enterprise:*:*:*:*:*:*:*:*

Mon, 10 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elastic Cloud Enterprise
Vendors & Products Elastic
Elastic elastic Cloud Enterprise

Fri, 07 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
Description Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is: post:/platform/configuration/security/service-accounts delete:/platform/configuration/security/service-accounts/{user_id} patch:/platform/configuration/security/service-accounts/{user_id} post:/platform/configuration/security/service-accounts/{user_id}/keys delete:/platform/configuration/security/service-accounts/{user_id}/keys/{api_key_id} patch:/user post:/users post:/users/auth/keys delete:/users/auth/keys delete:/users/auth/keys/_all delete:/users/auth/keys/{api_key_id} delete:/users/{user_id}/auth/keys delete:/users/{user_id}/auth/keys/{api_key_id} delete:/users/{user_name} patch:/users/{user_name}
Title Elastic Cloud Enterprise Improper Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2025-11-11T04:55:35.664Z

Reserved: 2025-04-16T03:24:04.511Z

Link: CVE-2025-37736

cve-icon Vulnrichment

Updated: 2025-11-10T16:02:34.104Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-07T23:15:44.350

Modified: 2025-12-11T21:00:54.740

Link: CVE-2025-37736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-10T09:33:45Z

Weaknesses