
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56143 is a denial-of-service vulnerability in Elastic Elasticsearch caused by Allocation of Resources Without Limits or Throttling (CWE-770). A user with elevated privileges can submit a specially crafted network request that triggers excessive memory consumption, potentially rendering the affected Elasticsearch node unavailable. The vulnerability affects Elasticsearch versions 8.0.0 through 8.19.19 and 9.0.0 through 9.2.8. It was published on September 1, 2026, with a patch released on September 3, 2026. It carries a CVSS v3.1 base score of 4.9 (Medium) (Elastic Advisory, MSRC).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling), where Elasticsearch fails to impose adequate constraints on memory allocation triggered by certain crafted requests. An authenticated attacker with elevated (high) privileges can exploit this over the network by submitting a specially crafted request that causes the node to allocate excessive memory without bound, consistent with CAPEC-130 (Excessive Allocation). No authentication bypass is involved — the attacker must already possess elevated privileges within the Elasticsearch cluster. No public proof-of-concept or detailed technical write-up has been identified at this time (Elastic Advisory, OSV).
Successful exploitation results in a high availability impact: the targeted Elasticsearch node becomes unavailable due to memory exhaustion, disrupting search and indexing operations for any applications or services dependent on that node. There is no confidentiality or integrity impact — the vulnerability is limited to denial of service. In clustered deployments, repeated exploitation could degrade or take down multiple nodes, potentially affecting the availability of the entire cluster (Elastic Advisory).
No public proof-of-concept exploit exists, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment indicates exploitation is currently "none" and not automatable. The EPSS score is approximately 0.31%, reflecting a low probability of near-term exploitation. Exploitation requires elevated privileges within the Elasticsearch environment, significantly limiting the attacker pool (Elastic Advisory, MSRC).
Elastic has released patched versions addressing this vulnerability: Elasticsearch 8.19.20 and Elasticsearch 9.3.0. Organizations should upgrade affected instances (8.0.0–8.19.19 and 9.0.0–9.2.8) to these fixed versions as the primary remediation. As interim measures, restrict elevated-privilege access to trusted administrators only, monitor Elasticsearch node memory consumption for unusual spikes, and implement resource limits and throttling policies at the application or infrastructure level (Elastic Advisory).
The vulnerability was covered as part of Microsoft's September 2026 Patch Tuesday roundup, which addressed 966 flaws in total, indicating broad industry awareness of the patch cycle (BleepingComputer). No notable independent researcher commentary or significant community discussion specific to this CVE has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."