Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2026-72686
6.5MEDIUM
What is CVE-2026-72686?
A vulnerability in Elasticsearch permits a low-privileged authenticated user to send a malicious request containing unvalidated input. The internal component processes this input recursively without imposing limits on its length, ultimately leading to a stack exhaustion. This unhandled fatal error results in the termination of the impacted node process, thereby causing a denial of service and disrupting operations.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.19
Elasticsearch 9.0.0 <= 9.4.4
Elasticsearch 9.5.0