AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-7018

HIGH · CVSS 8.8 EPSS 1.09%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-08-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-7018
Severity
HIGH
CVSS
8.8
EPSS
1.09%

Original NVD Description

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.