Resource exhaustion in Elasticsearch - CVE-2026-82294
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Elasticsearch when performing analytical aggregation searches. A remote user can cause excessive allocation to cause a denial of service.
Only configurations with analytical aggregation search capabilities enabled are vulnerable.