Elastic Cloud Enterprise (ECE) was found to contain a critical remote code execution (RCE) vulnerability, identified as CVE-2025-37729, which carries a CVSS score of 9.1, indicating its high severity. The flaw arises from improper neutralization of special elements in the Jinjava template engine, a component used within ECE’s configuration templates. Attackers with administrative access can exploit this vulnerability by submitting specially crafted strings that are evaluated by Jinjava, allowing them to execute arbitrary commands on the server. This could lead to exfiltration of sensitive information and full compromise of affected ECE deployments. The vulnerability specifically impacts ECE versions 2.5.0 up to and including 3.8.1, and versions 4.0.0 up to and including 4.0.1. Exploitation requires access to the ECE admin console and interaction with deployments configured with the Logging+Metrics feature enabled. By leveraging this flaw, a malicious actor can inject code through deployment plans and retrieve the results via ingested logs, effectively achieving server-side code execution. Elastic has responded by releasing patched versions 3.8.2 and 4.0.2, which address the issue by hardening the Jinjava variable evaluation process. The vulnerability was publicly disclosed in mid-October 2025, and security advisories urge all affected organizations to update their ECE installations immediately. The flaw is considered remotely exploitable, but only by users with administrative privileges, which somewhat limits the attack surface but does not diminish the potential impact. No evidence of exploitation in the wild has been reported at the time of disclosure, but the critical nature of the vulnerability has prompted urgent action from Elastic and the security community. The vulnerability was reported by a member of the Elastic security team, and details were published in both vendor advisories and CVE databases. Organizations using Elastic Cloud Enterprise are advised to review their access controls and ensure that only trusted personnel have administrative access. The incident highlights the risks associated with template injection vulnerabilities in cloud management platforms. Security teams are encouraged to monitor for any suspicious activity in ECE admin consoles and to apply the recommended patches without delay. The disclosure has also prompted discussions about the importance of input sanitization in template engines used in enterprise software. Elastic’s swift response and detailed advisories have been commended by the cybersecurity community. The vulnerability underscores the need for regular security reviews and prompt patch management in cloud environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Alongside the disclosure, Elastic released fixes for CVE-2025-37729 in Elastic Cloud Enterprise versions 3.8.2 and 4.0.2. The company also advised customers to monitor logs, review admin access, and disable Logging+Metrics on untrusted deployments.
Elastic disclosed a critical remote code execution vulnerability, CVE-2025-37729, affecting Elastic Cloud Enterprise via Jinjava template injection. The flaw impacts ECE versions 2.5.0 through 3.8.1 and 4.0.0 through 4.0.1, and requires administrative access to exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.