CVE-2026-94398: Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published Sep 26, 2026
·Updated
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Affected Software
1 affected component
Elastic Elasticsearch
Event History
Sep 26, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs low-level privileges. The vulnerability is remotely reachable over the network and does not require user interaction.
2
Does this affect confidentiality or data integrity?
The provided impact vector indicates no confidentiality or integrity impact. The stated impact is on availability, with a high availability impact.