Junglewise Threat Intelligence

CVE-2026-56149: Elastic Elasticsearch denial of service in machine learning component

CVE-2026-56149 · Severity: medium · CVSS 4.9 · Published 2026-07-01

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch is a search and analytics engine used to store and process large volumes of data. A vulnerability in its machine learning component allows a user with high-level permissions to crash the system by sending a specially crafted request. This can lead to a denial of service, making the affected data node unavailable for legitimate business operations.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in Elasticsearch's machine learning component. An attacker with elevated privileges (specifically the ability to create or manage trained models) can submit a specially crafted machine learning request that triggers excessive memory consumption. This leads to a denial of service (CAPEC-130) by rendering the affected node unavailable. The issue is reachable over the network without user interaction, though it requires high privileges. The vulnerability is resolved in versions 8.19.17, 9.3.6, and 9.4.3.

Affected products

  • Elastic Elasticsearch 8.0.0 to 8.19.16, 9.0.0 to 9.3.5, 9.4.0 to 9.4.2

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory
  • 2026-07-01: patched

References

Related threats