PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72685 Elastic CVE debrief

A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time, degrading the availability of indexing operations on the affected node.

Vendor
Elastic
Product
Elasticsearch
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-01
Advisory published
2026-08-13
Advisory updated
2026-09-01

Who should care

Elasticsearch administrators and users with indexing privileges should be aware of this vulnerability and take necessary precautions. This includes reviewing the affected versions, assessing exposure, and applying vendor patches or updates when available. Security teams and vulnerability management teams should also be informed about this issue to ensure proper prioritization and remediation efforts. Additionally, operators and platform teams may need to be involved in the remediation process, especially if the affected Elasticsearch nodes are part of a larger system or service. Monitoring and detection teams should also be aware of this vulnerability to ensure they can detect potential exploitation attempts or performance degradation related to this issue. Asset inventory management teams may need to review their deployments to identify potentially affected systems. Rollback and change window management teams should be prepared to support the remediation process, especially if emergency patches or updates are required. Source tracking and incident response teams should also be aware of this vulnerability to ensure they can respond effectively in case of an exploitation attempt or successful attack. Compensating controls, such as monitoring and detection, may be necessary while patches are being applied. The CVE record and NVD entry provide details about the vulnerability. Vendor advisory is available at discuss.elastic.co. Elasticsearch administrators should verify the affected versions (8.0.0 to 8.19.20, 9.0.0 to 9.4.5) and assess their exposure. Defenders should review the official advisory for specific guidance on mitigating this vulnerability. Additional information may be found in the Elastic security bulletin. This vulnerability may impact the confidentiality, integrity, or availability of data stored in Elasticsearch, and defenders should take necessary precautions to protect their deployments. The vulnerability can be exploited by a low-privileged authenticated user, which increases the attack surface. Therefore, it is essential to apply vendor patches or updates as soon as possible and to monitor the system for potential exploitation attempts or signs

Technical summary

CVE-2026-72685 is a vulnerability in Elasticsearch that allows a low-privileged authenticated user to submit a crafted document, occupying a worker thread and degrading indexing operations. The vulnerability affects Elasticsearch versions 8.0.0 to 8.19.20 and 9.0.0 to 9.4.5. This issue can lead to a denial-of-service (DoS) condition, impacting the availability of indexing operations on the affected node. Elasticsearch administrators should be aware of this vulnerability and take necessary precautions to protect their deployments.

Defensive priority

Medium-priority defensive actions are required to address this issue.

Recommended defensive actions

  • Inventory Elasticsearch nodes and verify affected versions (8.0.0 to 8.19.20, 9.0.0 to 9.4.5).
  • Restrict indexing privileges to necessary users.
  • Monitor indexing operations for performance degradation.
  • Apply vendor patches or updates when available.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability. Vendor advisory is available at discuss.elastic.co. Elasticsearch administrators should verify the affected versions (8.0.0 to 8.19.20, 9.0.0 to 9.4.5) and assess their exposure. Defenders should review the official advisory for specific guidance on mitigating this vulnerability. Additional information may be found in the Elastic security bulletin.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72685 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72685

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72685 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72685

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-security-update-esa-2026-77/389500

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.