CVE-2026-72685

A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time, degrading the availability of indexing operations on the affected node.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 20:17

Updated : 2026-09-01 15:04


NVD link : CVE-2026-72685

Mitre link : CVE-2026-72685

CVE.ORG link : CVE-2026-72685


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-407

Inefficient Algorithmic Complexity