Represented by Carahsoft ↗, Converge Technology Solutions ↗, World Wide Technology ↗
elastic.co ↗ · required email domain for this vendor's users
2 of 5 independent trust signals established
Elastic has 2 dimensions with established evidence. The rest have not been confirmed yet.
Not yet established: Independently verified · Operating durability · Disclosure posture
Has anyone other than the vendor confirmed this?
Nothing here has been confirmed by an independent third party yet.
Is this a real, durable business?
How long this vendor has been operating, and who stands behind them.
Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.
The platform admin controls the formula's weights.
Integrates with: 1Password ↗, ANY.RUN ↗, Akamai ↗, Alibaba Cloud ↗, Anomali ↗, Armis ↗, Auth0 ↗, Axonius ↗, Barracuda
No buyer reviews yet.
No ratings in this window yet.
Search-powered security analytics (Elastic Security). AI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →
Security headers (1/5) — checked 8/13/2026
Infrastructure & transparency signals
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local file…
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attac…
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.…
Drawn from this vendor's own public materials and authored to keep category questionnaires balanced. Gaps reflect capabilities not emphasized in public materials, not rankings.
Strengths: Open, search-powered SIEM with native endpoint/XDR and built-in workflows (no separate SOAR), with flexible deployment.
Gaps: Flexibility and openness can require more in-house engineering to operationalize.
Product information on this page is auto-generated by 0-Doubt from public sources and not yet confirmed by the vendor or an independent analyst, unless an item is individually labelled otherwise. How trust works →
What do they do when something goes wrong?
What their public record shows about handling vulnerabilities and outages.
Do they tell you the awkward things unprompted?
How much this vendor volunteers before you have to ask.
Are they still shipping, or coasting?
Whether this vendor is visibly still building.
Integrated by: 1Password, 1stProtect.ai, Abstract Security, Adaptive Security, AiStrike, Aikido Security, Andromeda Security, Anomali, Apono, Aqua Security, Bitsight, Chainguard, Cisco, Cloudlytics, ConnectWise, LLC, Corelight, Cribl, Cyberhaven, Cyera, D3 Security, Darktrace, Devtron, Dispel, Doppel, Edge Delta, Embed Security, Entro Security, Exaforce, Expel, Fleet Device Management, FossID, FusionAuth, Gigamon, Gurucul, Infisical, Intezer, Kentik, LMNTRIX, MCK Communications, Mindflow, Monad, Netmaker, OctoXLabs, Offroad, Operant AI, Opsera, OutThink, Prophet Security, Qevlar AI, Red Canary, RiskXchange, Seceon Inc, Seemplicity, Simbian, Sinaptic.AI, Siren, SpyCloud, Strobes Security, Sumo Logic, Swimlane, Sysdig, Teleport, Teleskope, Tenzir, ThreatAware, Token Security, Torq, UncommonX, Unosecur, UpGuard, Vijilan, Wiz, Zero Networks, ZeroFox, Zscaler, eSentire, isMalicious, rebasoft, torii, tychon
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would …
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to imprope…
Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sy…
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Elastic Search). Supported versions that are affected are 8.55 and 8.56. Easily exploitabl…
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous run…
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, an…
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, …
Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigation…
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative acces…
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authenticati…
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerabilit…
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with…
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire p…
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified imp…
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks …
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Elastic Search). Supported versions that are affected are 8.55 and 8.56. Easily exploit…
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.