CVE-2017-8449: Elastic X-Pack

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.

Affected products

  • Elastic X-Pack: from 5.2.0, up to and including 5.2.2

Published 2017-06-16. Last modified 2026-06-17.