OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94408

MEDIUM · CVSS 4.9 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to uncontrolled resource consumption, which can result in a denial of service due to excessive resource allocation. This issue could allow an attacker to overwhelm the system, leading to degraded performance or complete service interruption. Organizations using Elasticsearch should prioritize addressing this vulnerability to maintain service availability and protect against potential disruptions.

CVE
CVE-2026-94408
Severity
MEDIUM
CVSS
4.9
EPSS
0.44%

Original NVD Description

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

Related CVEs

Other vulnerabilities affecting the same vendor(s)