Denial of Service Vulnerability in APM Server by Elastic
CVE-2026-78594

4.9MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
2 September 2026

What is CVE-2026-78594?

A vulnerability in Elastic's APM Server allows an authenticated user with write access to potentially exploit the system by storing specially crafted, highly compressed data. When processed, this data can cause excessive memory allocation, leading to a persistent denial of service. The issue manifests every time the APM Server is started, as it exhausts the available memory, resulting in the termination of the process. To restore normal operations, the malicious content must be removed from storage.

Affected Version(s)

Apm Server 8.0.0 <= 8.19.19

Apm Server 9.0.0 <= 9.4.4

Apm Server 9.5.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.