Executive brief
Elasticsearch, a widely-used search and analytics engine, contains a resource consumption vulnerability that allows an authenticated attacker to trigger excessive memory or CPU allocation. An attacker could exploit this to cause a denial of service, making the search service unavailable to legitimate users and disrupting business operations that depend on real-time data indexing and retrieval.
Technical details
An uncontrolled resource consumption flaw (CWE-400) in Elasticsearch allows authenticated users to trigger excessive allocation of system resources (CAPEC-130), leading to denial of service. The vulnerability requires valid authentication credentials and network access to the Elasticsearch API. Versions 8.12.0–8.19.21, 9.0.0–9.4.6, and 9.5.0–9.5.3 are affected; patches are available in versions 8.19.22, 9.4.7, and 9.5.4.
Affected products
- Elastic Elasticsearch 8.12.0 to 8.19.21; 9.0.0 to 9.4.6; 9.5.0 to 9.5.3
Timeline
- 2026-09-26: disclosed: CVE-2026-94398 published
- 2026-09-25: patched: Fixed in Elasticsearch 8.19.22, 9.4.7, 9.5.4