{"id":"CVE-2020-7009","aliases":["BIT-elasticsearch-2020-7009","GHSA-gfv5-grx2-9jw2"],"url":"https://o3.security/vulnerability/CVE-2020-7009","summary":"Improper Privilege Management in Elasticsearch","details":"Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.","published":"2020-03-31T19:15:14.447Z","modified":"2026-07-08T20:29:31.084307Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.elasticsearch:elasticsearch","fixedVersion":"6.8.8"},{"ecosystem":"Maven","name":"org.elasticsearch:elasticsearch","fixedVersion":"7.6.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200403-0004/"},{"type":"ADVISORY","url":"https://www.elastic.co/community/security/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:29:31.084307Z"}}