Uncontrolled Resource Consumption in Elasticsearch by Elastic
CVE-2026-94408

4.9MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-94408?

A vulnerability in Elasticsearch has been identified that allows for uncontrolled resource consumption, potentially leading to denial of service. This issue arises from improper handling of resource allocation, which can be exploited to exhaust system resources, disrupting service availability. Organizations using affected versions should take immediate action to mitigate potential risks and enhance their cybersecurity posture.

Affected Version(s)

Elasticsearch 8.0.0 <= 8.19.21

Elasticsearch 9.0.0 <= 9.4.6

Elasticsearch 9.5.0 <= 9.5.2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.