Elastic
Elasticsearch: vulnerabilidades y CVE
Elasticsearch tiene 87 vulnerabilidades publicadas, 44 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE87
Últimos 12 meses44
Críticas2
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-3120 | Alta (8.1) | 89% | ⚠ Explotación activa | 28 jul 2014 | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only… |
| CVE-2015-1427 | Crítica (9.8) | 100% | ⚠ Explotación activa | 17 feb 2015 | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94408 | Media (4.9) | 0.44% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94399 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94398 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94397 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94396 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-82300 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). |
| CVE-2026-82294 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). |
| CVE-2026-82409 | Alta (8.4) | 0.27% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and… |
| CVE-2026-92468 | Alta (7.1) | 0.48% | — | 16 sept 2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name… |
| CVE-2026-89261 | Media (6.9) | 0.83% | — | 11 sept 2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can… |
| CVE-2026-78593 | Media (4.3) | 0.29% | — | 3 sept 2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script… |
| CVE-2026-78607 | Alta (7.1) | 0.33% | — | 1 sept 2026 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound… |
| CVE-2026-78605 | Media (5.9) | 0.34% | — | 1 sept 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment… |
| CVE-2026-72649 | Alta (8.8) | 0.92% | — | 1 sept 2026 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause… |
| CVE-2026-56143 | Media (4.9) | 0.44% | — | 1 sept 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted… |
| CVE-2026-72687 | Media (6.5) | 0.42% | — | 13 ago 2026 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it… |
| CVE-2026-72686 | Media (6.5) | 0.52% | — | 13 ago 2026 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and… |
| CVE-2026-72685 | Media (4.3) | 0.37% | — | 13 ago 2026 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker… |
| CVE-2026-72684 | Media (6.5) | 0.42% | — | 13 ago 2026 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to… |
| CVE-2026-72683 | Media (6.5) | 0.52% | — | 13 ago 2026 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to… |
| CVE-2026-72679 | Media (6.5) | 0.47% | — | 13 ago 2026 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread… |
| CVE-2026-72678 | Media (6.5) | 0.47% | — | 13 ago 2026 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a… |
| CVE-2026-72656 | Media (6.5) | 0.42% | — | 13 ago 2026 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries… |
| CVE-2026-72647 | Media (6.5) | 0.42% | — | 13 ago 2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one… |
| CVE-2026-72645 | Media (6.5) | 0.42% | — | 13 ago 2026 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit… |
| CVE-2026-72642 | Alta (8.8) | 0.60% | — | 13 ago 2026 | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating… |
| CVE-2026-72639 | Media (6.5) | 0.42% | — | 13 ago 2026 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated… |
| CVE-2026-72638 | Media (6.5) | 0.42% | — | 13 ago 2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single… |
| CVE-2026-72636 | Media (6.5) | 0.42% | — | 13 ago 2026 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is… |
| CVE-2026-63263 | Media (6.5) | 0.42% | — | 22 jul 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.