Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-49090

Elasticsearch: crafted bulk request causes sustained high CPU

Technology

Elasticsearch

CVSS Score

6.5 / 10.0

Affected Versions

Up to 7.17.23; 8.0.0 to before 8.15.0

Upstream Fix

7.17.24; 8.15.0

Published

July 1, 2026

OSSeva Coverage

Fixed upstream

Description

An authenticated user able to call the bulk API can submit a specially crafted bulk request that causes sustained high CPU consumption, leaving the node unable to process requests. The fix shipped in 7.17.24 and 8.15.0 and was disclosed in July 2026. Elastic lists no workaround. CVSS is Elastic's score as the CNA.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running Up to 7.17.23; 8.0.0 to before 8.15.0, you need this patch. Book a discovery call to get covered.