CVE-2026-103009
- EPSS 0.24%
- Veröffentlicht 06.10.2026 19:31:53
- Zuletzt bearbeitet 07.10.2026 13:42:52
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorizat...
CVE-2026-103008
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:51
- Zuletzt bearbeitet 07.10.2026 13:42:52
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an...
CVE-2026-103007
- EPSS 0.34%
- Veröffentlicht 06.10.2026 19:31:50
- Zuletzt bearbeitet 07.10.2026 13:42:52
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in ...
CVE-2026-103006
- EPSS 0.4%
- Veröffentlicht 06.10.2026 19:31:49
- Zuletzt bearbeitet 07.10.2026 13:42:52
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its se...
CVE-2026-103005
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:47
- Zuletzt bearbeitet 07.10.2026 13:42:52
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled ...
CVE-2026-102411
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:43
- Zuletzt bearbeitet 07.10.2026 13:42:52
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template r...
CVE-2026-102409
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:40
- Zuletzt bearbeitet 07.10.2026 13:42:52
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
CVE-2026-102408
- EPSS 0.34%
- Veröffentlicht 06.10.2026 19:31:39
- Zuletzt bearbeitet 07.10.2026 13:42:52
Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular ...
CVE-2026-102407
- EPSS 0.22%
- Veröffentlicht 06.10.2026 19:31:37
- Zuletzt bearbeitet 07.10.2026 13:42:52
Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could...
CVE-2026-102404
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:34
- Zuletzt bearbeitet 07.10.2026 13:42:52
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the qu...