Known Vulnerabilities for Elasticsearch by Anynines
Listed below are 1 of the newest known vulnerabilities associated with "Elasticsearch" by "Anynines".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100696 json | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional El... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-94408 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-94399 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-94398 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-94397 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-94396 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-92468 json | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that... | Not Provided | 2026-09-16 | 2026-09-18 |
| CVE-2026-92466 json | zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPe... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-90772 json | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML ... | Not Provided | 2026-09-13 | 2026-09-24 |
| CVE-2026-89261 json | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allo... | Not Provided | 2026-09-11 | 2026-09-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Anynines | Elasticsearch | 2.1.2 | |||
| Application | Anynines | Elasticsearch | 2.1.1 | |||
| Application | Anynines | Elasticsearch | 2.1.0 | |||
| Application | Anynines | Elasticsearch | 2.0.2 | |||
| Application | Anynines | Elasticsearch | 2.0.1 | |||
| Application | Anynines | Elasticsearch | 1.0.0 | |||
| Application | Anynines | Elasticsearch | 0.9.4 | |||
| Application | Anynines | Elasticsearch | 0.9.3 | |||
| Application | Anynines | Elasticsearch | 0.9.2 | |||
| Application | Anynines | Elasticsearch | 0.9.1 | |||
| Application | Anynines | Elasticsearch | 0.9.0 | |||
| Application | Anynines | Elasticsearch | - |