SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-56145

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to a denial of service attack due to uncontrolled resource consumption, allowing low-privileged authenticated users to execute specially crafted EQL sequence queries that lead to excessive memory allocation and node crashes. Organizations using Elasticsearch should prioritize this vulnerability to prevent potential service disruptions, particularly those with user access to execute queries on controlled indexes. Immediate remediation is recommended to mitigate the risk of exploitation.

CVE
CVE-2026-56145
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)