CVE-2025-37729: Elastic Cloud Enterprise
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.
Affected products
- Elastic Elastic Cloud Enterprise: from 2.5.0, before 3.8.2 (fixed in 3.8.2); from 4.0.0, before 4.0.2 (fixed in 4.0.2)
Published 2025-10-13. Last modified 2026-10-08.