Description
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that terminates the Elasticsearch node. The condition can be triggered repeatedly, including by queries embedded in shared resources, causing persistent cluster unavailability.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch allows a low‑privileged authenticated user to submit a crafted query that causes the query‑processing engine to allocate memory without bounds. The resulting memory pressure brings the node to an out‑of‑memory state, terminating the process and rendering the cluster unavailable. Repeated exploitation of the same query can lead to persistent denial of service.

Affected Systems

Affected are Elastic Elasticsearch instances that have not applied the recent security update. The vulnerability is known in the 8.x and 9.x families; any deployment that accepts arbitrary queries from low‑privileged accounts is at risk. The product is Elastic:Elasticsearch, and the fix is distributed through the official Elastic Security Advisory.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so a definitive exploitation probability cannot be quantified; however, the lack of a KEV listing suggests no widespread public exploitation yet. The attack requires authenticated access, making it relatively constrained but still dangerous in multi‑tenant or shared tenancy environments where an attacker may have limited permissions to submit queries. Monitor for repeated anomalous query patterns and ensure user privileges are restrained.

Generated by OpenCVE AI on October 6, 2026 at 20:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Elastic security update (ESA‑2026‑185) to upgrade Elasticsearch to the patched versions (e.g., 8.19.23, 9.4.8, 9.5.5).
  • Restrict low‑privileged users from executing arbitrary queries by tightening role permissions and enforcing least privilege in query handling.
  • Monitor cluster memory usage and set alerts for abnormal consumption; consider disabling or throttling potentially dangerous query patterns if the patch cannot be applied immediately.

Generated by OpenCVE AI on October 6, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that terminates the Elasticsearch node. The condition can be triggered repeatedly, including by queries embedded in shared resources, causing persistent cluster unavailability.
Title Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:57:23.769Z

Reserved: 2026-09-29T02:06:02.425Z

Link: CVE-2026-102404

cve-icon Vulnrichment

Updated: 2026-10-06T19:57:19.296Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:12.333

Modified: 2026-10-06T20:17:12.333

Link: CVE-2026-102404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption