Executive brief
Elasticsearch, a search and analytics engine used in many enterprise systems, contains a flaw that allows authenticated users to trigger excessive resource allocation, causing the service to become unavailable. An attacker with valid credentials could exploit this to disrupt business operations by making Elasticsearch unresponsive to legitimate requests.
Technical details
Uncontrolled resource consumption (CWE-400) in Elasticsearch permits authenticated attackers to allocate excessive resources, leading to denial of service. The vulnerability requires login credentials (PR:L) and network access. Fixes are available in versions 9.4.7 and 9.5.4; no workarounds exist for affected versions.
Affected products
- Elastic Elasticsearch 9.2.0 to 9.4.6, 9.5.0 to 9.5.3
Timeline
- 2026-09-25: disclosed
- 2026-09-25: patched: Fixed in versions 9.4.7 and 9.5.4