Memory Exhaustion in Elasticsearch by Authenticated Users
CVE-2026-72678

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72678?

Elasticsearch contains a flaw where it does not properly validate the size value derived from user input before utilizing it for memory allocation. This issue allows an authenticated user with merely read privileges to craft a specific request that forces the Elasticsearch node into making an overly large memory allocation attempt. This can lead to memory exhaustion, causing a fatal error and resulting in denial of service for that node, ultimately impacting the health of the entire cluster. This vulnerability can be triggered by a single request, making it particularly concerning as it bypasses the need for excessive workloads to exploit.

Affected Version(s)

Elasticsearch 8.19.0 <= 8.19.19

Elasticsearch 9.4.0 <= 9.4.4

Elasticsearch 9.5.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.