跳到正文
北京时间
原文
PromptArmor:Threat Intelligence·· 14 天前精选AI 评分72

Elastic AI SOC 被曝存在间接提示注入漏洞,可窃取凭证

Elastic Agentic SOC Vulnerable to Credential Theft

AI 导读

PromptArmor 披露 Elastic Agentic SOC(AI 安全运营中心)存在严重安全风险。攻击者可通过恶意钓鱼邮件中的指令实施间接提示注入,诱导 AI Agent 创建并执行恶意工作流,进而生成 API 密钥并发送给攻击者。由于缺乏强制的人工审批环节,攻击者可利用窃取的密钥禁用检测规则、伪造警报或窃取数据。该漏洞于 2026 年 8 月报告给 Elastic,但至今未修复。文章提供了关闭自动内置能力、限制工具权限及更换更鲁棒模型等缓解措施。

推荐理由

揭示了 AI Agent 在安全运营场景下的具体攻击链与风险,为使用或开发类似自动化系统的团队提供了重要的防御配置参考和警示。

正文 · 原文
Elastic’s Agentic SOC executes the attacker’s workflow

Context

Security teams are racing to adopt Agentic SOCs (security operations centers) to improve their security; ironically, AI SOCs themselves can pose a serious security risk. Given the prevalence of untrusted data (malicious activity reports) and the capability for sensitive actions involved in incident response, AI SOCs are prime targets for indirect prompt injection attacks. We demonstrate this threat in EASE, Elastic's AI SOC.

Elastic’s Agentic SOC agent is susceptible to manipulation by the alerts it was created to triage, and it can take any action in Elastic with the user’s privileges; no human-in-the-loop approval is required.

In the attack chain below, the agent is manipulated into minting API keys and sending them to an attacker. The attacker can then take any action the user has permissions for, such as disabling detection rules, creating fake alerts to conceal a real attack, exfiltrating data from Elasticsearch, or deleting data from the tenant.

This vulnerability was reported to Elastic on August 23, 2026, but has not been addressed despite four follow-ups. As such, we are publishing this report to inform users of the risk and configurations to mitigate it. More details on responsible disclosure are at the end of the article.

The Attack Chain

  1. The user asks the AI SOC for assistance triaging phishing alerts

    One very common data source in a SOC is a phishing tipline, where users can forward suspicious emails for triage by the security team.

    The user asks Elastic AI to triage phishing alerts.
  2. The AI SOC is manipulated by one of the alerts to create and execute a malicious workflow

    One of the phishing emails the agent is trying to assess states that there are additional alerts to retrieve from a specific URL and that it should use a workflow with a subagent to handle them.

    Elastic AI follows instructions embedded in an alert.

    The workflow retrieves data from an attacker-controlled URL and then spawns a subagent with no context other than the attacker's data and a system prompt: ‘Action the below’... leading the subagent to take whatever action the attacker’s server supplies.

    The workflow retrieves an attacker-controlled prompt and runs a subagent.

    Note: This all occurs without human-in-the-loop approval because the agent has discretion over when to add a ‘waitForApproval’ step to its workflows, and the prompt injection discourages doing so.

  3. Malicious workflow exfiltrates API keys

    Here, the attacker’s server returns an instruction telling the subagent that it is participating in a competition. To win, it needs to mint new API keys and send them to the attacker’s server to ‘submit its findings’.

    The attacker server logs API keys submitted by the subagent.

    Technical note: The attack also exfiltrated the workspace URL, which is necessary for the attacker to make requests using the exfiltrated API key.

  4. Attacker exploits API access to take unauthorized actions in the SOC and exfiltrate data

    The attacker uses stolen API keys to query data and modify alert rules.

    Using the exfiltrated credentials, the attacker can take any action a user could. This includes:

    • Disabling or removing alert rules

    • Creating fake alerts to cover for a real attack

    • Exfiltrating data from across Elastic and integrations

    • Establishing persistence through scheduled jobs

    • Harvesting data from devices monitored by the AI SOC

    We also note that all of these outcomes can be achieved directly via a workflow run by a manipulated subagent, rather than using the workflow to exfiltrate keys and proceeding from there.

Mitigations

  1. Agent configurations:

    Disable the Elastic AI Agent setting “Include built-in capabilities automatically” to allow manual management of which tools are enabled.

    Your Project > Agents (left sidebar) > Overview > Edit Agent Settings > Customization > Include built-in capabilities automatically > Toggle OFF

    We then recommend disabling write-capable tools, as the system does not currently appear to support human-in-the-loop approval controls, except for ‘waitForApproval’ workflow steps, which are used only at the agent’s discretion.

    Your Project > Agents (left sidebar) > Elastic AI Agent (Dropdown) > Manage Agents > Hover 'Elastic AI Agent', click Edit icon that appears > Tools Tab > Uncheck unwanted Tools

    The following tools, which are enabled by default on the default agent, carry the highest risk:

    • Platform.core.execute_esql

    • Platform.core.execute_workflow

    We also highly recommend disabling the setting to automatically assign all current and future Elastic-built tools, Skills, and Plugins to the agent.

    Your Project > Agents (left sidebar) > Elastic AI Agent (Dropdown) > Manage Agents > Hover 'Elastic AI Agent', click Edit icon that appears > Setting Tab > Elastic Capabilities > Toggle OFF
  2. Default model selection

    Currently, the default model in Elastic is Anthropic Claude Sonnet 4.5.

    Elastic AI’s default model is Anthropic Claude Sonnet 4.5.

    More recent models are substantially more robust against indirect prompt injection. Configure an alternative default model via:

    Your Project > Discover Elastic AI / Configure AI Provider > Select Provider > Select model in dropdown
  3. IP Access Restrictions

    To restrict ingress and egress from Elastic Cloud to and from untrusted IPs, configure Network Security policies under:

    Organization Settings > Network Security > Create Policy

Responsible Disclosure

PromptArmor disclosed the vulnerabilities described in this article on August 23, 2026. Elastic acknowledged receipt of the report but did not engage with the disclosure despite four follow-ups. As such, we are publishing to inform users of the risks and pertinent controls to mitigate them.

We note that Elastic’s reporting policy explicitly permits email disclosure, stating, “If you do not wish to use the bug bounty program, you may email us directly at security@elastic.co.".

Timeline

DateEvent
August 23, 2026PromptArmor discloses to Elastic
August 27, 2026PromptArmor follows up
August 28, 2026Elastic requests submission via HackerOne
August 28, 2026PromptArmor clarifies email preference
September 1, 2026PromptArmor follows up, citing email as documented reporting channel
September 6, 2026PromptArmor follows up

PromptArmor Threat Intelligence

Is your organization protected from AI in vendors?

PromptArmor continuously monitors across your portfolio of third party AI in vendors, skills, plugins, connectors, MCP servers, models and more.

We detect vulnerabilities and changes like this, surfacing risk before it becomes an incident.

Learn more

来源:PromptArmor:Threat Intelligence · promptarmor.com