SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-94398

MEDIUM · CVSS 6.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

Elasticsearch is susceptible to an uncontrolled resource consumption vulnerability that can result in denial of service due to excessive resource allocation. This flaw allows attackers to overwhelm the system, potentially causing service disruptions. Organizations utilizing Elasticsearch should prioritize remediation efforts to mitigate the risk of service outages.

CVE
CVE-2026-94398
Severity
MEDIUM
CVSS
6.5
EPSS
0.41%

Original NVD Description

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

Related CVEs

Other vulnerabilities affecting the same vendor(s)