Elasticsearch Vulnerability Affects Low-Privileged Users
CVE-2026-72685
4.3MEDIUM
What is CVE-2026-72685?
A vulnerability in Elasticsearch permits low-privileged authenticated users, capable of indexing documents, to manipulate the system by submitting a small, crafted document. This input consumes a worker thread from a limited pool for an extended period, leading to decreased availability for indexing operations on the impacted node, affecting overall system performance.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.19
Elasticsearch 9.0.0 <= 9.4.4