Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-49090
Elasticsearch: crafted bulk request causes sustained high CPU
Technology
Elasticsearch
CVSS Score
6.5 / 10.0
Affected Versions
Up to 7.17.23; 8.0.0 to before 8.15.0
Upstream Fix
7.17.24; 8.15.0
Published
July 1, 2026
OSSeva Coverage
Fixed upstream
Description
An authenticated user able to call the bulk API can submit a specially crafted bulk request that causes sustained high CPU consumption, leaving the node unable to process requests. The fix shipped in 7.17.24 and 8.15.0 and was disclosed in July 2026. Elastic lists no workaround. CVSS is Elastic's score as the CNA.
Is your Elasticsearch deployment affected?
If you're running Up to 7.17.23; 8.0.0 to before 8.15.0, you need this patch. Book a discovery call to get covered.