# Elastic Cloud Enterprise (ECE) 3.8.3 and 4.0.3 Security Update (ESA-2025-22)

**URL:** <https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-3-and-4-0-3-security-update-esa-2025-22/383132>\
**Category:** Security Announcements\
**Created:** [October 31, 2025, 5:36pm UTC](https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-3-and-4-0-3-security-update-esa-2025-22/383132 "2025-10-31T17:36:53Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 31, 2025, 5:36pm UTC](https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-3-and-4-0-3-security-update-esa-2025-22/383132/1 "2025-10-31T17:36:53Z")

</div>

**Elastic Cloud Enterprise Improper Authorizatio** n **(ESA-2025-22)**

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is:

```auto
post:/platform/configuration/security/service-accounts
delete:/platform/configuration/security/service-accounts/{user_id}
patch:/platform/configuration/security/service-accounts/{user_id}
post:/platform/configuration/security/service-accounts/{user_id}/keys
delete:/platform/configuration/security/service-accounts/{user_id}/keys/{api_key_id}
patch:/user
post:/users
post:/users/auth/keys
delete:/users/auth/keys
delete:/users/auth/keys/_all
delete:/users/auth/keys/{api_key_id}
delete:/users/{user_id}/auth/keys
delete:/users/{user_id}/auth/keys/{api_key_id}
delete:/users/{user_name}
patch:/users/{user_name} 

```

**Affected Versions:**

Elastic Cloud Enterprise versions after 3.8.0 and up to including 3.8.2

Elastic Cloud Enterprise versions after 4.0.0 and up to including 4.0.2

**Affected Configurations:**

This issue affects all ECE users.

**Solutions and Mitigations:**

Users should upgrade to version 3.8.3 and 4.0.3. In addition to the upgrade, Elastic Cloud Enterprise users should investigate whether there exist any users or service accounts that have been created by the readonly user and potentially delete them. The [following tooling](https://github.com/elastic/cleanup-ece-users) offers this functionality. Elastic advises extreme caution while deleting users, to ensure that only the necessary ones are deleted.

**For Users that Cannot Upgrade:**

Users that cannot upgrade, should also use the [provided tooling](https://github.com/elastic/cleanup-ece-users) to list users or service accounts that have been created by the readonly user and potentially delete them.

**Severity:** CVSSv3.1: 8.8(High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H}

**CVE ID** : CVE-2025-37736

---

_[View the full topic](https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-3-and-4-0-3-security-update-esa-2025-22/383132)._
