SB2026090169 - Multiple vulnerabilities in Elasticsearch
Published: September 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-78605)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to inconsistent interpretation of HTTP requests in the HTTP/1.1 listener when handling crafted HTTP requests through an intermediate proxy or load balancer. A remote attacker can send crafted HTTP requests to disclose sensitive information.
Successful exploitation requires an intermediate proxy or load balancer that shares and reuses persistent backend connections across independent client sessions.
2) Deserialization of Untrusted Data (CVE-ID: CVE-2026-72649)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in the Elasticsearch machine learning component when processing a specially crafted trained model artifact. A remote user can upload and deploy a crafted trained model artifact to execute arbitrary code.
Only deployments with machine learning capacity enabled are affected.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-56143)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Elasticsearch when handling specially crafted requests. A remote privileged user can submit a specially crafted request to cause a denial of service.
The issue may cause excessive memory consumption and render the affected node unavailable.
4) Missing Authorization (CVE-ID: CVE-2026-78607)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the Elasticsearch custom inference service when handling inference execution requests. A remote user can direct outbound inference traffic to a destination of their choosing to disclose sensitive information.
Only deployments using the custom inference service type with secret-backed configuration are vulnerable.
Remediation
Install update from vendor's website.
References
- https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-141/390092
- https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-114/390087
- https://discuss.elastic.co/t/elasticsearch-8-19-20-9-3-0-security-update-esa-2026-47/390084
- https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-9-5-1-security-update-esa-2026-143/390094