CVE-2014-3120: Elasticsearch Remote Code Execution Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 88.6% chance of exploitation in the next 30 days.
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
Affected products
- Elastic Elasticsearch: before 1.2.0 (fixed in 1.2.0)
Published 2014-07-28. Last modified 2026-06-17.