Description
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (node termination)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an uncontrolled recursion flaw that allows an authenticated user with low privileges to trigger the termination of an Elasticsearch node. This results in a denial of service by disrupting cluster availability. The flaw is classified as CWE-674 and is a manifestation of Excessive Allocation, which can cause the system to exhaust resources or crash.

Affected Systems

Elastic’s Elasticsearch product is affected. No specific version information is provided in the current data, so all deployed instances of Elasticsearch should be considered potentially impacted until the vendor’s update status is confirmed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attack is likely through an authenticated session with low privileges, inferred from the description.

Generated by OpenCVE AI on October 6, 2026 at 20:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Elasticsearch to the latest supported version released in Elastic's security update 2026-190 (e.g., 9.5.5 or later).
  • Restrict low‑privilege authenticated users from performing cluster‑management actions that could trigger node termination.
  • Enable cluster health monitoring to detect and automatically recover from sudden node termination events.

Generated by OpenCVE AI on October 6, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
Title Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:55:40.589Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102409

cve-icon Vulnrichment

Updated: 2026-10-06T19:55:36.853Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:12.907

Modified: 2026-10-06T20:17:12.907

Link: CVE-2026-102409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses