
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-37729 is a Server-Side Template Injection (SSTI) vulnerability in Elastic Cloud Enterprise (ECE) affecting the Jinjava template engine. It allows a malicious actor with Admin-level access to exfiltrate sensitive information and execute arbitrary commands via a specially crafted string where Jinjava variables are evaluated. Affected versions include ECE 2.5.0 through 3.8.1 and 4.0.0 through 4.0.1. The vulnerability was disclosed on October 13, 2025, with patches available in versions 3.8.2 and 4.0.2. It carries a CVSS v3.1 base score of 7.2 (High) per NVD, and 9.1 (Critical) per ENISA's EUVD scoring (Elastic Advisory).
The root cause is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine), specifically within ECE's use of the Jinjava templating engine (Elastic Advisory). An authenticated administrator can supply a specially crafted string containing Jinjava template expressions (e.g., {{ ... }} syntax) that are evaluated server-side without adequate sanitization, enabling template injection. The attack vector is network-based, requires no user interaction, but does require high privileges (Admin access), limiting the attack surface to compromised or malicious administrators (ZeroPath).
Successful exploitation allows an authenticated admin to exfiltrate sensitive information from the ECE environment and execute unauthorized commands, compromising confidentiality, integrity, and availability of the system (Elastic Advisory). The scope of impact includes the ECE management plane, potentially exposing cluster credentials, configuration secrets, and other sensitive operational data. Given ECE's role as an orchestration platform for Elasticsearch clusters, a successful attack could facilitate lateral movement into managed Elasticsearch deployments (SecurityOnline).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Elastic Advisory). The EPSS score is approximately 0.044%, reflecting a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for Admin-level credentials, significantly reducing the attack surface to insider threats or scenarios where admin accounts are compromised (ZeroPath).
{{ 'freemarker.template.utility.Execute'?new()('id') }} or equivalent Jinjava RCE expressions) designed to execute OS commands or read sensitive files.{{, }}, or other template delimiters.sh, bash, curl, wget) indicating OS command execution via template injection.Elastic has released patched versions ECE 3.8.2 and ECE 4.0.2, which address this vulnerability — upgrading to these versions is the primary recommended remediation (Elastic Advisory). As interim mitigations, organizations should strictly limit and audit admin access to ECE, enforce multi-factor authentication (MFA) for admin accounts, and monitor admin activity for anomalous behavior. Input validation and sanitization controls for template engine contexts should also be reviewed as a defense-in-depth measure.
Security media outlets including GBHackers, CyberSecurityNews, and SecurityOnline covered the vulnerability shortly after disclosure, with several characterizing it as a critical RCE risk due to the ENISA CVSS score of 9.1 (SecurityOnline, GBHackers). The vulnerability was also noted in The Hacker News weekly recap and Hawk-Eye's weekly threat landscape digest, indicating moderate community interest. Social media activity on Bluesky and Mastodon included brief mentions from infosec community accounts, though overall discussion volume was limited given the high-privilege requirement for exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."