CVE-2026-102409: Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published Oct 6, 2026
·Updated
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
Affected Software
1 affected component
Elastic Elasticsearch
Event History
Oct 6, 2026
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness