What is CVE-2026-63144?
CVE-2026-63144 is an Uncontrolled Recursion vulnerability (CWE-674) in Elasticsearch that can lead to denial of service. A low-privileged authenticated user with read-level index access can submit a specially crafted search request to trigger unbounded recursive processing. Updating Elasticsearch to the latest patched version is recommended.
Azərbaycanca: CVE-2026-63144 Elasticsearch-də nəzarətsiz rekursiya (Uncontrolled Recursion) zəifliyidir. Aşağı səviyyəli autentifikasiya olunmuş istifadəçi xüsusi hazırlanmış axtarış sorğusu ilə xidmətin dayanmasına (Denial of Service) səbəb ola bilər. Elasticsearch-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Is authentication required to exploit CVE-2026-63144?
Yes, authentication is required to exploit CVE-2026-63144. The vulnerability can only be exploited by a low-privileged authenticated user with read-level index access.
What is the impact of CVE-2026-63144?
CVE-2026-63144 is an Uncontrolled Recursion vulnerability that can lead to denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.