Multiple vulnerabilities in Elasticsearch (CVSS Base Score 8.8) allow a remote attacker to execute arbitrary code and conduct denial-of-service attacks. Affected versions are Open Source Elasticsearch prior to 8.19.20, prior to 9.4.5, and prior to 9.5.1. A mitigation is available, and users should upgrade to the specified fixed versions or apply the provided mitigation.
[WID-SEC-2026-2841] Elasticsearch: Mehrere Schwachstellen CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 13.08.2026 Stand 14.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Windows Produktbeschreibung Elasticsearch ist eine Open Source, verteilte Echtzeit-Suche und Analyse-Engine. Produkte 13.08.2026 Open Source Elasticsearch <8.19.20 Open Source Elasticsearch <9.4.5 Open Source Elasticsearch <9.5.1 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Elasticsearch ausnutzen, um beliebigen Programmcode auszufĂĽhren, und um einen Denial of Service Angriff durchzufĂĽhren. CVE Informationen Versionshistorie Feedback zum Advisory geben