Elastic Elasticsearch是荷兰Elastic公司开源的一个搜索分析引擎。 Elastic Elasticsearch存在资源管理错误漏洞,该漏洞源于资源不受控制消耗(CWE-400),可能导致经过身份验证的用户提交特制批量请求引发持续高CPU消耗,致使受影响节点无法处理请求。以下版本受到影响:8.0.0版本至8.14.3版本和7.0.0版本至7.17.23版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 8.0.0≤ 8.14.3 |
affected |
7.0.0≤ 7.17.23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 8.0.0 ~ 8.14.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49091 | 8.0 HIGH | Improper Output Neutralization for Logs in Kibana Leading to Log Injection |
| CVE-2026-49087 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-56150 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of |
| CVE-2026-56148 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-56151 | 6.5 MEDIUM | Improper Input Validation in Kibana Leading to Denial of Service |
| CVE-2026-56152 | 5.3 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-56149 | 4.9 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-49088 | 4.4 MEDIUM | Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosu |
No comments yet