Known Vulnerabilities for Elasticsearch by Anynines
Listed below are 1 of the newest known vulnerabilities associated with "Elasticsearch" by "Anynines".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63263 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CA... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-63144 json | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submit... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63140 json | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A speci... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63136 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-13... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-56149 json | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-56148 json | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An au... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-56145 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-13... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-56144 json | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit i... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-54350 json | Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app rea... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-49095 json | Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An a... | Not Provided | 2026-05-28 | 2026-05-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Anynines | Elasticsearch | 2.1.2 | |||
| Application | Anynines | Elasticsearch | 2.1.1 | |||
| Application | Anynines | Elasticsearch | 2.1.0 | |||
| Application | Anynines | Elasticsearch | 2.0.2 | |||
| Application | Anynines | Elasticsearch | 2.0.1 | |||
| Application | Anynines | Elasticsearch | 1.0.0 | |||
| Application | Anynines | Elasticsearch | 0.9.4 | |||
| Application | Anynines | Elasticsearch | 0.9.3 | |||
| Application | Anynines | Elasticsearch | 0.9.2 | |||
| Application | Anynines | Elasticsearch | 0.9.1 | |||
| Application | Anynines | Elasticsearch | 0.9.0 | |||
| Application | Anynines | Elasticsearch | - |