PT-2026-71792 · Elastic · Elasticsearch

CVE-2026-72683

·

Published

2026-08-13

·

Updated

2026-08-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Elasticsearch (affected versions not specified)
Description An authenticated user with sufficient privileges can trigger a denial of service by sending a request to the 'simulate pipeline' API endpoint. This action creates a self-referential data structure, which causes an internal component to recurse without bound. The resulting unhandled fatal error terminates the affected node process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2026-72683
CVE-2026-72683

Affected Products

Elasticsearch