CVE-2026-49090: Elastic Elasticsearch
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.
Affected products
- Elastic Elasticsearch: from 7.0.0, before 7.17.24 (fixed in 7.17.24); from 8.0.0, before 8.15.0 (fixed in 8.15.0)
Published 2026-07-01. Last modified 2026-07-02.