CVE-2017-8446: Elasticsearch X-Pack
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
Affected products
- Elasticsearch X-Pack: up to and including 5.5.1
- Elasticsearch X-Pack Reporting: up to and including 2.4.5
Published 2017-08-18. Last modified 2026-06-17.