VendorsElasticelasticsearchany version
Vulnerabilities

Elastic Elasticsearch any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Published 2015-02-17 · Analyzed
9.8KEV2 PoCEPSS 0.999
CVE-2015-5377
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability
Published 2018-03-06 · Modified
9.8EPSS 0.143
CVE-2018-3831
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.
Published 2018-09-19 · Modified
8.8EPSS 0.020
CVE-2020-7009
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
Published 2020-03-31 · Modified
8.8EPSS 0.016
CVE-2020-7014
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.
Published 2020-06-03 · Modified
8.8EPSS 0.015
CVE-2026-72649
Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
Published 2026-09-01 · Analyzed
8.8EPSS 0.009
CVE-2021-37937
Elasticsearch privilege escalation
Published 2023-11-22 · Modified
8.8EPSS 0.007
CVE-2026-72642
Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
Published 2026-08-13 · Analyzed
8.8EPSS 0.006
CVE-2014-3120
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
Published 2014-07-28 · Analyzed
8.1KEV2 PoCEPSS 0.886
CVE-2019-7611
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security.dls_fls.enabled set to false, certain permission checks are skipped when users perform one of the actions mentioned above, to make existing data available under a new index/alias name. This could result in an attacker gaining additional permissions against a restricted index.
Published 2019-03-25 · Modified
8.1EPSS 0.021
CVE-2023-46674
Elasticsearch-hadoop Unsafe Deserialization
Published 2023-12-05 · Modified
7.8EPSS 0.002
CVE-2023-31419
Elasticsearch StackOverflow vulnerability
Published 2023-10-26 · Modified
7.5EPSS 0.617
CVE-2022-23712
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
Published 2022-06-06 · Modified
7.5EPSS 0.074
CVE-2023-31418
Elasticsearch uncontrolled resource consumption
Published 2023-10-26 · Modified
7.5EPSS 0.021
CVE-2024-23450
Elasticsearch Uncontrolled Resource Consumption vulnerability
Published 2024-03-27 · Analyzed
7.5EPSS 0.013
CVE-2023-46673
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Published 2023-11-22 · Modified
7.5EPSS 0.008
CVE-2024-52979
Elasticsearch Uncontrolled Resource Consumption vulnerability
Published 2025-05-01 · Analyzed
7.5EPSS 0.006
CVE-2024-43709
Elasticsearch allocation of resources without limits or throttling leads to crash
Published 2025-01-21 · Modified
7.5EPSS 0.006
CVE-2024-52981
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.
Published 2025-04-08 · Analyzed
7.5EPSS 0.006
CVE-2024-23444
Elasticsearch elasticsearch-certutil csr fails to encrypt private key
Published 2024-07-31 · Modified
7.5EPSS 0.002
CVE-2025-37731
Elasticsearch Improper Authentication
Published 2025-12-15 · Analyzed
7.4EPSS 0.002
CVE-2026-78607
Missing Authorization in Elasticsearch Leading to Information Disclosure
Published 2026-09-01 · Analyzed
7.1EPSS 0.003
CVE-2021-22145
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Published 2021-07-21 · Modified
6.51 PoCEPSS 0.762
CVE-2021-22144
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Published 2021-07-26 · Modified
6.5EPSS 0.022
CVE-2018-17244
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.
Published 2018-12-20 · Modified
6.5EPSS 0.015
CVE-2020-7019
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
Published 2020-08-18 · Modified
6.5EPSS 0.012
CVE-2021-22147
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
Published 2021-09-15 · Modified
6.5EPSS 0.010
CVE-2018-3826
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.
Published 2018-09-19 · Modified
6.5EPSS 0.007
CVE-2024-52980
Elasticsearch Uncontrolled Resource Consumption vulnerability
Published 2025-04-08 · Analyzed
6.5EPSS 0.005
CVE-2026-72686
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.005
CVE-2026-72683
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.005
CVE-2024-23451
Elasticsearch Incorrect Authorization in the Remote Cluster Security API key based security model
Published 2024-03-27 · Analyzed
6.5EPSS 0.005
CVE-2026-56148
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-07-01 · Analyzed
6.5EPSS 0.005
CVE-2026-56145
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.005
CVE-2026-72679
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.005
CVE-2026-72678
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.005
CVE-2024-12539
Elasticsearch Incorrect Authorization
Published 2024-12-17 · Analyzed
6.5EPSS 0.005
CVE-2024-23445
Elasticsearch Remote Cluster Search Cross Cluster API Key insufficient restrictions
Published 2024-06-12 · Analyzed
6.5EPSS 0.005
CVE-2023-49921
An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.
Published 2024-07-26 · Modified
6.5EPSS 0.004
CVE-2026-63140
Reachable Assertion in Elasticsearch Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
1 / 2Next →