CVE-2024-52975: Elastic Fleet Server

Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.

Affected products

  • Elastic Fleet Server: from 8.13.0, before 8.15.0 (fixed in 8.15.0)

Published 2025-01-23. Last modified 2026-06-17.