« Volver al listado

Elastic

Elasticsearch: vulnerabilidades y CVE

Elasticsearch tiene 87 vulnerabilidades publicadas, 44 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE87
Últimos 12 meses44
Críticas2
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2014-3120Alta (8.1)89%⚠ Explotación activa28 jul 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only…
CVE-2015-1427Crítica (9.8)100%⚠ Explotación activa17 feb 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94408Media (4.9)0.44%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94399Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94398Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94397Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94396Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-82300Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
CVE-2026-82294Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
CVE-2026-82409Alta (8.4)0.27%—23 sept 2026
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and…
CVE-2026-92468Alta (7.1)0.48%—16 sept 2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name…
CVE-2026-89261Media (6.9)0.83%—11 sept 2026
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can…
CVE-2026-78593Media (4.3)0.29%—3 sept 2026
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script…
CVE-2026-78607Alta (7.1)0.33%—1 sept 2026
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound…
CVE-2026-78605Media (5.9)0.34%—1 sept 2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment…
CVE-2026-72649Alta (8.8)0.92%—1 sept 2026
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause…
CVE-2026-56143Media (4.9)0.44%—1 sept 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted…
CVE-2026-72687Media (6.5)0.42%—13 ago 2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it…
CVE-2026-72686Media (6.5)0.52%—13 ago 2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and…
CVE-2026-72685Media (4.3)0.37%—13 ago 2026
A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker…
CVE-2026-72684Media (6.5)0.42%—13 ago 2026
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to…
CVE-2026-72683Media (6.5)0.52%—13 ago 2026
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to…
CVE-2026-72679Media (6.5)0.47%—13 ago 2026
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread…
CVE-2026-72678Media (6.5)0.47%—13 ago 2026
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a…
CVE-2026-72656Media (6.5)0.42%—13 ago 2026
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries…
CVE-2026-72647Media (6.5)0.42%—13 ago 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one…
CVE-2026-72645Media (6.5)0.42%—13 ago 2026
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit…
CVE-2026-72642Alta (8.8)0.60%—13 ago 2026
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating…
CVE-2026-72639Media (6.5)0.42%—13 ago 2026
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated…
CVE-2026-72638Media (6.5)0.42%—13 ago 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single…
CVE-2026-72636Media (6.5)0.42%—13 ago 2026
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is…
CVE-2026-63263Media (6.5)0.42%—22 jul 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services13
  2. T1499.004 Application or System Exploitation8
  3. T1190 Exploit Public-Facing Application3
  4. T1059 Command and Scripting Interpreter2
  5. T1005 Data from Local System1
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Elastic