CVE-2026-82300: Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published Sep 26, 2026
·Updated
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Affected Software
1 affected component
Elastic Elasticsearch
Event History
Sep 26, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access is required and the attacker must already have low-level privileges. User interaction is not required.
2
Can this vulnerability expose or alter Elasticsearch data?
The reported CVSS impact assigns no confidentiality or integrity impact. Its reported impact is limited to availability, with a high availability impact.