Junglewise Threat Intelligence

CVE-2026-94398: Elasticsearch uncontrolled resource consumption denial of service

CVE-2026-94398 · Severity: medium · CVSS 6.5 · Published 2026-09-26

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a widely-used search and analytics engine, contains a resource consumption vulnerability that allows an authenticated attacker to trigger excessive memory or CPU allocation. An attacker could exploit this to cause a denial of service, making the search service unavailable to legitimate users and disrupting business operations that depend on real-time data indexing and retrieval.

Technical details

An uncontrolled resource consumption flaw (CWE-400) in Elasticsearch allows authenticated users to trigger excessive allocation of system resources (CAPEC-130), leading to denial of service. The vulnerability requires valid authentication credentials and network access to the Elasticsearch API. Versions 8.12.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3 are affected; patches are available in versions 8.19.22, 9.4.7, and 9.5.4.

Affected products

  • Elastic Elasticsearch 8.12.0 to 8.19.21; 9.0.0 to 9.4.6; 9.5.0 to 9.5.3

Timeline

  • 2026-09-26: disclosed: CVE-2026-94398 published
  • 2026-09-25: patched: Fixed in Elasticsearch 8.19.22, 9.4.7, 9.5.4

References

Related threats