PromptArmor
Threat Intel

Elastic Agentic SOC Vulnerable to Credential Theft

Elastic’s Agentic SOC is vulnerable to credential theft and system manipulation via indirect prompt injection in SOC data feeds. No human-in-the-loop is required.

Elastic’s Agentic SOC executes the attacker’s workflow

Context

Security teams are racing to adopt Agentic SOCs (security operations centers) to improve their security; ironically, AI SOCs themselves can pose a serious security risk. Given the prevalence of untrusted data (malicious activity reports) and the capability for sensitive actions involved in incident response, AI SOCs are prime targets for indirect prompt injection attacks. We demonstrate this threat in EASE, Elastic's AI SOC.

Elastic’s Agentic SOC agent is susceptible to manipulation by the alerts it was created to triage, and it can take any action in Elastic with the user’s privileges; no human-in-the-loop approval is required.

In the attack chain below, the agent is manipulated into minting API keys and sending them to an attacker. The attacker can then take any action the user has permissions for, such as disabling detection rules, creating fake alerts to conceal a real attack, exfiltrating data from Elasticsearch, or deleting data from the tenant.

This vulnerability was reported to Elastic on August 23, 2026, but has not been addressed despite four follow-ups. As such, we are publishing this report to inform users of the risk and configurations to mitigate it. More details on responsible disclosure are at the end of the article.

The Attack Chain

  1. The user asks the AI SOC for assistance triaging phishing alerts

    One very common data source in a SOC is a phishing tipline, where users can forward suspicious emails for triage by the security team.

    The user asks Elastic AI to triage phishing alerts.
  2. The AI SOC is manipulated by one of the alerts to create and execute a malicious workflow

    One of the phishing emails the agent is trying to assess states that there are additional alerts to retrieve from a specific URL and that it should use a workflow with a subagent to handle them.

    Elastic AI follows instructions embedded in an alert.

    The workflow retrieves data from an attacker-controlled URL and then spawns a subagent with no context other than the attacker's data and a system prompt: ‘Action the below’... leading the subagent to take whatever action the attacker’s server supplies.

    The workflow retrieves an attacker-controlled prompt and runs a subagent.

    Note: This all occurs without human-in-the-loop approval because the agent has discretion over when to add a ‘waitForApproval’ step to its workflows, and the prompt injection discourages doing so.

  3. Malicious workflow exfiltrates API keys

    Here, the attacker’s server returns an instruction telling the subagent that it is participating in a competition. To win, it needs to mint new API keys and send them to the attacker’s server to ‘submit its findings’.

    The attacker server logs API keys submitted by the subagent.

    Technical note: The attack also exfiltrated the workspace URL, which is necessary for the attacker to make requests using the exfiltrated API key.

  4. Attacker exploits API access to take unauthorized actions in the SOC and exfiltrate data

    The attacker uses stolen API keys to query data and modify alert rules.

    Using the exfiltrated credentials, the attacker can take any action a user could. This includes:

    • Disabling or removing alert rules
    • Creating fake alerts to cover for a real attack
    • Exfiltrating data from across Elastic and integrations
    • Establishing persistence through scheduled jobs
    • Harvesting data from devices monitored by the AI SOC

    We also note that all of these outcomes can be achieved directly via a workflow run by a manipulated subagent, rather than using the workflow to exfiltrate keys and proceeding from there.

Mitigations

  1. Agent configurations:

    Disable the Elastic AI Agent setting “Include built-in capabilities automatically” to allow manual management of which tools are enabled.

    Your Project > Agents (left sidebar) > Overview > Edit Agent Settings > Customization > Include built-in capabilities automatically > Toggle OFF

    We then recommend disabling write-capable tools, as the system does not currently appear to support human-in-the-loop approval controls, except for ‘waitForApproval’ workflow steps, which are used only at the agent’s discretion.

    Your Project > Agents (left sidebar) > Elastic AI Agent (Dropdown) > Manage Agents > Hover 'Elastic AI Agent', click Edit icon that appears > Tools Tab > Uncheck unwanted Tools

    The following tools, which are enabled by default on the default agent, carry the highest risk:

    • Platform.core.execute_esql
    • Platform.core.execute_workflow

    We also highly recommend disabling the setting to automatically assign all current and future Elastic-built tools, Skills, and Plugins to the agent.

    Your Project > Agents (left sidebar) > Elastic AI Agent (Dropdown) > Manage Agents > Hover 'Elastic AI Agent', click Edit icon that appears > Setting Tab > Elastic Capabilities > Toggle OFF
  2. Default model selection

    Currently, the default model in Elastic is Anthropic Claude Sonnet 4.5.

    Elastic AI’s default model is Anthropic Claude Sonnet 4.5.

    More recent models are substantially more robust against indirect prompt injection. Configure an alternative default model via:

    Your Project > Discover Elastic AI / Configure AI Provider > Select Provider > Select model in dropdown
  3. IP Access Restrictions

    To restrict ingress and egress from Elastic Cloud to and from untrusted IPs, configure Network Security policies under:

    Organization Settings > Network Security > Create Policy

Responsible Disclosure

PromptArmor disclosed the vulnerabilities described in this article on August 23, 2026. Elastic acknowledged receipt of the report but did not engage with the disclosure despite four follow-ups. As such, we are publishing to inform users of the risks and pertinent controls to mitigate them.

We note that Elastic’s reporting policy explicitly permits email disclosure, stating, “If you do not wish to use the bug bounty program, you may email us directly at security@elastic.co.".

Timeline

DateEvent
August 23, 2026PromptArmor discloses to Elastic
August 27, 2026PromptArmor follows up
August 28, 2026Elastic requests submission via HackerOne
August 28, 2026PromptArmor clarifies email preference
September 1, 2026PromptArmor follows up, citing email as documented reporting channel
September 6, 2026PromptArmor follows up

PromptArmor Threat Intelligence

Is your organization protected from AI in vendors?

PromptArmor continuously monitors across your portfolio of third party AI in vendors, skills, plugins, connectors, MCP servers, models and more.

We detect vulnerabilities and changes like this, surfacing risk before it becomes an incident.

Learn more