Junglewise Threat Intelligence

CVE-2026-94408: Elastic Elasticsearch denial of service via resource exhaustion

CVE-2026-94408 · Severity: medium · CVSS 4.9 · Published 2026-09-26

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a widely used search and analytics engine, contains a vulnerability that allows attackers with administrative privileges to exhaust system resources and cause a denial of service. An attacker could trigger excessive memory or CPU allocation on Elasticsearch clusters, making the search and analytics service unavailable to legitimate users and potentially disrupting dependent applications and data pipelines.

Technical details

Uncontrolled resource consumption (CWE-400) in Elasticsearch permits denial of service through excessive allocation (CAPEC-130) with network-based attack vectors. The vulnerability requires high-level privileges (PR:H), no user interaction, and affects all configurations. Attackers can consume excessive resources leading to service unavailability; patches are available in versions 8.19.22, 9.4.7, and 9.5.3.

Affected products

  • Elastic Elasticsearch 8.0.0 through 8.19.21, 9.0.0 through 9.4.6, 9.5.0 through 9.5.2

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: Fixed in Elasticsearch 8.19.22, 9.4.7, 9.5.3

References

Related threats