Description
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Published: 2026-09-26
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an uncontrolled resource consumption flaw that can cause excessive allocation of memory or other resources in Elasticsearch, leading to a denial of service. It is classified as CWE-400 and can be triggered by requests that force the system to allocate more resources than intended, ultimately exhausting available capacity.

Affected Systems

The affected vendor and product are Elastic: Elasticsearch. No specific version information is provided in the data, so any running instance of Elasticsearch may be susceptible until an update is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, so the exact exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, via HTTP or cluster management interfaces that allow construction of resource-intensive queries. The attack requires network access to the Elasticsearch cluster and the ability to send sufficiently large or complex requests. If exploited, the cluster may become unresponsive to legitimate workloads, impacting availability for all users of the service.

Generated by OpenCVE AI on September 26, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Elasticsearch to a version that includes the official fix for the uncontrolled resource consumption issue.
  • Configure request size limits, resource quotas, and cluster allocation settings to reduce the impact of potentially demanding queries.
  • Monitor cluster health metrics and set alert thresholds for sudden spikes in memory usage or allocation requests to detect and mitigate attacks early.

Generated by OpenCVE AI on September 26, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 26 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elasticsearch
Vendors & Products Elastic
Elastic elasticsearch

Sat, 26 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Title Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Elastic Elasticsearch
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-26T23:00:58.356Z

Reserved: 2026-08-28T11:30:29.847Z

Link: CVE-2026-82294

cve-icon Vulnrichment

Updated: 2026-09-26T23:00:55.608Z

cve-icon NVD

Status : Received

Published: 2026-09-26T21:16:55.783

Modified: 2026-09-26T23:16:36.720

Link: CVE-2026-82294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T22:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption