OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-102411

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to a Denial of Service attack due to improper resource allocation, allowing users with the *manage_index_templates* privilege to register multiple metadata resources that, while individually limited, can collectively exhaust system memory. This can lead to out-of-memory errors and cause the affected node to fail. Organizations utilizing Elasticsearch should prioritize this vulnerability to prevent potential service disruptions.

CVE
CVE-2026-102411
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such resources are retrieved together. A user holding the *manage_index_templates* cluster privilege can register multiple resources each within the individual limit. Retrieving them together materializes all of their metadata values in memory at once, exhausting available heap and causing the affected node to fail with an out-of-memory error, resulting in a denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)