# Elastic Stack 6.8.8 and 7.6.2 security update

**URL:** <https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920>\
**Category:** Security Announcements\
**Created:** [March 31, 2020, 5:08pm UTC](https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920 "2020-03-31T17:08:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [March 31, 2020, 5:08pm UTC](https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920/1 "2020-03-31T17:08:34Z")

</div>

**Elasticsearch API key privilege escalation (ESA-2020-02)**

Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

**Affected Versions**  
All versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 are vulnerable to this issue.

**Solutions and Mitigations**  
Users should upgrade to Elasticsearch version 7.6.2 or 6.8.8. Users who are unable to upgrade can mitigate this flaw by disabling API keys by setting `xpack.security.authc.api_key.enabled` to false in the elasticsearch.yml file.

Additional details about this change can be found here:  
[Elasticsearch API key privileges](https://www.elastic.co/guide/en/elasticsearch/reference/current/breaking-changes-7.6.html#breaking_76_security_changes)

**CVSSv3: 5.7 - AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N**  
**CVE ID: [CVE-2020-7009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7009)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:51am UTC](https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920/2 "2022-11-04T07:51:39Z")

</div>


