Junglewise Threat Intelligence

CVE-2026-94396: Elasticsearch denial of service via uncontrolled resource consumption

CVE-2026-94396 · Severity: medium · CVSS 6.5 · Published 2026-09-26

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a search and analytics engine used in many enterprise systems, contains a flaw that allows authenticated users to trigger excessive resource allocation, causing the service to become unavailable. An attacker with valid credentials could exploit this to disrupt business operations by making Elasticsearch unresponsive to legitimate requests.

Technical details

Uncontrolled resource consumption (CWE-400) in Elasticsearch permits authenticated attackers to allocate excessive resources, leading to denial of service. The vulnerability requires login credentials (PR:L) and network access. Fixes are available in versions 9.4.7 and 9.5.4; no workarounds exist for affected versions.

Affected products

  • Elastic Elasticsearch 9.2.0 to 9.4.6, 9.5.0 to 9.5.3

Timeline

  • 2026-09-25: disclosed
  • 2026-09-25: patched: Fixed in versions 9.4.7 and 9.5.4

References

Related threats