Elastic Observability · Vulnerability Disclosure

Elastic Observability Vulnerability Disclosure

Vulnerability disclosure

Elastic Observability runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

AIOpsObservabilityAPMLoggingMetricsTracingOpenTelemetryMonitoringTelemetry
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@elastic.co

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-29'
method: searched
source: https://www.elastic.co/product-security
provider: Elastic Observability
providerId: elastic-observability
published: true
policy_url: https://www.elastic.co/product-security
contact: security@elastic.co
pgp_fingerprint: 1224 D1A5 72A7 3755 B61A 377B 14D6 5EE0 D2AE 61D2
security_txt:
  served: true
  host: api.elastic-cloud.com
  url: https://api.elastic-cloud.com/.well-known/security.txt
  probed: '2026-08-29'
  probe_status: 200
  content_type: text/plain
  file: ../well-known/elastic-observability-security.txt
  fields:
    Contact: security@elastic.co
    Encryption: openpgp4fpr:1224D1A572A73755B61A377B14D65EE0D2AE61D2
    Hiring: https://www.elastic.co/about/careers
    Policy: https://www.elastic.co/cloud/security
  note: >-
    www.elastic.co and elastic.co both 404 /.well-known/security.txt — only the API host serves it.
    The file carries no Expires field, which RFC 9116 requires.
bug_bounty:
  offered: true
  platform: HackerOne
  url: https://hackerone.com/elastic
  probed: '2026-08-29'
  probe_status: 200
  exclusivity: >-
    "If you wish to be considered for a bounty, you must submit your report exclusively through our
    official bug bounty program" — reports sent by email are not eligible for a bounty.
disclosure:
  model: coordinated vulnerability disclosure
  embargo_request: >-
    Elastic asks researchers not to "post or share any information about potential vulnerabilities
    in any public forum until we have researched and responded to the issue via our official
    channels."
  advisories: Elastic Security Advisory (ESA)
  advisories_url: https://discuss.elastic.co/c/announcements/security-announcements
  cna: true
  cna_note: Elastic is an authorized CVE Numbering Authority and assigns its own CVE IDs.
safe_harbor:
  published: false
  note: No explicit safe-harbour / legal-protection language appears in the policy.
response_sla:
  published: false

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/elastic-observability-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.