← elastic

elastic / elasticsearch

24 known vulnerabilities in elastic elasticsearch.

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-72649 Medium 0.6% 8.8 Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learnin…
CVE-2026-72642 Medium 0.3% 8.8 The native inference process that Elasticsearch uses to evaluate uploaded machin…
CVE-2026-72683 Low 0.4% 6.5 A flaw in Elasticsearch allows an authenticated user with the privileges require…
CVE-2026-72686 Low 0.4% 6.5 A flaw in Elasticsearch allows a low-privileged authenticated user to submit a s…
CVE-2026-56145 Low 0.3% 6.5 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial …
CVE-2026-72678 Low 0.3% 6.5 Elasticsearch does not validate a size value taken from a user-supplied input be…
CVE-2026-72679 Low 0.3% 6.5 Elasticsearch does not apply its configurable input length restriction to a user…
CVE-2026-56143 Low 0.3% 4.9 Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch …
CVE-2026-72636 Low 0.3% 6.5 Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper c…
CVE-2026-72638 Low 0.3% 6.5 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service …
CVE-2026-72639 Low 0.3% 6.5 Elasticsearch does not enforce an upper bound on a user-supplied count accepted …
CVE-2026-72645 Low 0.3% 6.5 Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead …
CVE-2026-72647 Low 0.3% 6.5 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service …
CVE-2026-72656 Low 0.3% 6.5 Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query process…
CVE-2026-72684 Low 0.3% 6.5 A flaw in Elasticsearch allows an authenticated user holding only read privilege…
CVE-2026-72687 Low 0.3% 6.5 A flaw in Elasticsearch allows a low-privileged authenticated user to submit a s…
CVE-2026-72685 Low 0.3% 4.3 A flaw in Elasticsearch allows a low-privileged authenticated user who can index…
CVE-2026-63136 Low 0.2% 6.5 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial …
CVE-2026-63140 Low 0.2% 6.5 Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via…
CVE-2026-63144 Low 0.2% 6.5 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service …
CVE-2026-63263 Low 0.2% 6.5 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial …
CVE-2026-56144 Low 0.2% 5.3 Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated us…
CVE-2026-78605 Low 0.2% 5.9 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444…
CVE-2026-78607 Low 0.2% 5.4 Missing Authorization (CWE-862) in the Elasticsearch custom inference service ca…