CVE-2025-37729 is a critical template injection vulnerability in Elastic Cloud Enterprise (ECE) caused by improper neutralization of special elements in the Jinjava template engine. ECE processes certain configuration fields and deployment-plan-related input through Jinjava; a malicious actor with authenticated Admin access can supply a specially crafted string that causes Jinjava variables and expressions to be evaluated in an unsafe context. According to the provided content, exploitation can occur via crafted payloads submitted through deployment plans, particularly in contexts where Logging+Metrics is enabled. Successful exploitation allows the attacker to abuse the template evaluation context to exfiltrate sensitive information and issue commands, effectively resulting in arbitrary command execution depending on the backend execution context. The issue affects ECE versions 2.5.0 through 3.8.1 and 4.0.0 through 4.0.1, and is fixed in 3.8.2 and 4.0.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
(payload.name : int3rpr3t3r or payload.name : forPath) to identify possible exploitation attempts, reviewing and restricting ECE admin-console access, limiting admin privileges to trusted accounts only, and disabling Logging+Metrics on untrusted deployments where feasible.Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate Elastic Cloud Enterprise vulnerability referenced only in the detection guidance section, apparently involving malicious payload injection and deployment plan processing in the ECE admin console.
A critical remote code execution vulnerability in Elastic Cloud due to Jinjava template injection, with a CVSS score of 9.1.
A critical remote code execution vulnerability in Elastic Cloud Enterprise (ECE) due to improper input sanitization in the Jinjava template engine, allowing attackers with admin access to execute arbitrary commands or exfiltrate data via template injection.
A critical template injection vulnerability in Elastic Cloud Enterprise caused by improper neutralization of special elements in the Jinjava template engine, allowing an authenticated admin to exfiltrate sensitive data and potentially execute arbitrary commands.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.