References https://www.venustech.com.cn/new_type/aqtg/20251110/28948.html https://cn-sec.com/archives/4672094.html https://cn-sec.com/archives/4650724.html https://zeropath.com/blog/cve-2025-37736-elastic-cloud-enterprise-authorization-summary https://securityonline.info/elastic-patches-high-severity-privilege-escalation-flaw-in-elastic-cloud-enterprise-cve-2025-37736/ https://purple-ops.io/blog/elastic-ece-privilege-escalation https://github.com/advisories/GHSA-5p88-6546-29fh https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-2-and-4-0-2-security-update-esa-2025-21/382641
Related Vulnerabilities金蝶eascloud管理控制端任意文件上传关于U9 cloud存在接口XML注入漏洞的安全通告关于U9 cloud存在接口SQL注入漏洞的安全通告关于U9 cloud存在接口无授权访问漏洞的安全通告关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告关于U9 cloud接口存在BinaryFormatter反序列化漏洞的安全通告英華達|全家寶 Cloud - Insecure Direct Object Reference用友U8Cloud MailApproveServlet存在SQL注入漏洞用友U8cloud /u8cloud/extsystem/dst SQL 注入漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞