SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-56143

MEDIUM · CVSS 4.9 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to a denial of service due to improper resource allocation, allowing users with elevated privileges to submit crafted requests that lead to excessive memory consumption. This can result in the affected node becoming unavailable, impacting service availability. Organizations utilizing Elasticsearch, particularly those with elevated user access, should prioritize addressing this vulnerability to mitigate potential disruptions.

CVE
CVE-2026-56143
Severity
MEDIUM
CVSS
4.9
EPSS
0.31%

Original NVD Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)