Elasticsearch 中存在未受控递归漏洞(CWE-674),该漏洞可通过过度分配攻击(CAPEC-130)允许权限较低但已认证的用户终止 Elasticsearch 节点,从而导致服务拒绝(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 9.2.0≤ 9.2.8 |
affected |
9.3.0≤ 9.3.8 |
affected | ||
9.4.0≤ 9.4.7 |
affected | ||
9.5.0≤ 9.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 9.2.0 ~ 9.2.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102406 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data In |
| CVE-2026-103007 | 7.2 HIGH | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation |
| CVE-2026-103009 | 7.1 HIGH | Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information D |
| CVE-2026-102412 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-102411 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-102404 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-103008 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-103005 | 6.5 MEDIUM | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
| CVE-2026-103006 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102413 | 6.2 MEDIUM | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-102407 | 5.4 MEDIUM | Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification |
| CVE-2026-102410 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-102408 | 4.3 MEDIUM | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service |
No comments yet