Executive brief
Elasticsearch, a widely used search and analytics engine, contains a vulnerability that allows attackers with administrative privileges to exhaust system resources and cause a denial of service. An attacker could trigger excessive memory or CPU allocation on Elasticsearch clusters, making the search and analytics service unavailable to legitimate users and potentially disrupting dependent applications and data pipelines.
Technical details
Uncontrolled resource consumption (CWE-400) in Elasticsearch permits denial of service through excessive allocation (CAPEC-130) with network-based attack vectors. The vulnerability requires high-level privileges (PR:H), no user interaction, and affects all configurations. Attackers can consume excessive resources leading to service unavailability; patches are available in versions 8.19.22, 9.4.7, and 9.5.3.
Affected products
- Elastic Elasticsearch 8.0.0 through 8.19.21, 9.0.0 through 9.4.6, 9.5.0 through 9.5.2
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Fixed in Elasticsearch 8.19.22, 9.4.7, 9.5.3