CVE-2015-1427: Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 99.9% chance of exploitation in the next 30 days.
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Affected products
- Elastic Elasticsearch: before 1.3.8 (fixed in 1.3.8); from 1.4.0, before 1.4.3 (fixed in 1.4.3)
- Red Hat Fuse: version 1.0.0 only
Published 2015-02-17. Last modified 2026-06-17.