Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2026-72683
6.5MEDIUM
What is CVE-2026-72683?
A vulnerability in Elasticsearch permits an authenticated user with necessary privileges to exploit the simulate pipeline API endpoint, leading to the creation of a self-referential data structure. When processed by an internal component, this structure triggers unbounded recursion, resulting in a fatal error that the execution path does not handle. This condition ultimately causes the process running the affected node to terminate, resulting in a Denial of Service.
Affected Version(s)
Elasticsearch 5.0.0 <= 8.19.18
Elasticsearch 9.3.0 <= 9.3.7
Elasticsearch 9.4.0 <= 9.4.3