What is CVE-2026-56145?
An uncontrolled resource consumption vulnerability (CWE-400) in Elasticsearch can lead to denial of service. A low-privileged authenticated user with control over an index can send a specially crafted EQL sequence query to trigger excessive allocation. Updating to the latest version of Elasticsearch is recommended.
Azərbaycanca: Elasticsearch-də nəzarətsiz resurs istehlakı (CWE-400) zəifliyi aşkar edilib. Aşağı səlahiyyətli autentifikasiya olunmuş istifadəçi, idarə etdiyi indeks üzərində xüsusi hazırlanmış EQL sequence sorğusu göndərərək həddindən artıq resurs ayrılmasına səbəb olub denial of service yarada bilər. Elasticsearch-in ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What level of access does an attacker need to exploit CVE-2026-56145 in Elasticsearch?
The attacker must be a low-privileged authenticated user with control over an index.
What is the potential impact of CVE-2026-56145?
It can lead to denial of service by triggering excessive resource allocation through a specially crafted EQL sequence query.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.