Elastic Elasticsearch是荷兰Elastic公司开源的一个搜索分析引擎。 Elastic Elasticsearch存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致权限高的用户提交特制机器学习请求,引起过度内存消耗,可能导致受影响节点不可用,从而导致拒绝服务攻击。以下版本受到影响:9.4.2及之前版本、9.3.5及之前版本和8.19.16及之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 9.4.0≤ 9.4.2 |
affected |
9.0.0≤ 9.3.5 |
affected | ||
8.0.0≤ 8.19.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 9.4.0 ~ 9.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49091 | 8.0 HIGH | Improper Output Neutralization for Logs in Kibana Leading to Log Injection |
| CVE-2026-49090 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-49087 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-56150 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of |
| CVE-2026-56148 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-56151 | 6.5 MEDIUM | Improper Input Validation in Kibana Leading to Denial of Service |
| CVE-2026-56152 | 5.3 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-49088 | 4.4 MEDIUM | Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosu |
No comments yet