CVE-2026-56148Disclosure(elastic / elasticsearch)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch elastic elasticsearch systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • elasticsearch

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
elasticsearch

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Seth Kraft@skraft09
    Patch

    Proud to share that CVE-2026-56148 has now been published! 🎉 The issue was resolved in versions 8.19.17, 9.3.6, and 9.4.3 of Elasticsearch. https://discuss.elastic.co/t/elasticsearch-8-19-17-9-3-6-9-4-3-security-update-esa-2026-42/387439 #TogetherWeHitHarder

    Post summary

    The tweet announces CVE-2026-56148, indicates it has been patched in Elasticsearch releases 8.19.17, 9.3.6, and 9.4.3, and references Elastic’s discussion thread for further details.

    01010157
    415 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56148 Denial of Service via Uncontrolled Recursion in Elasticsearch Authenticated Queries https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56148

    Post summary

    The text announces CVE-2026-56148, describing it as a denial‑of‑service vulnerability caused by uncontrolled recursion in authenticated Elasticsearch queries, without providing PoC, exploit, or remediation details.

    00000104
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelasticelasticsearch---

Explore more