Elasticsearch
Vendor:
First CVE: Jul 28, 2014 · Active for 11 years
56
Total CVEs
More Total CVEs than 98% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
3.6%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Elasticsearch over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2014
11 years ago
Most Recent CVE
Jul 22, 2026
6 days ago
CVE Severity & Scoring
Elasticsearch56 CVEs
63%
32%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.6%)
Network53 (94.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low49 (87.5%)
High7 (12.5%)
Unknown0 (0.0%)
User Interaction
None55 (98.2%)
Unknown0 (0.0%)
Required1 (1.8%)
Privileges Required
Low31 (55.4%)
High5 (8.9%)
None20 (35.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1427CRITICAL The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell comm | Feb 17, 2015 | 9.8 | 99 | YES | YES |
CVE-2014-3120HIGH The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source pa | Jul 28, 2014 | 8.1 | 97 | YES | YES |
CVE-2021-22145MEDIUM A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submi | Jul 21, 2021 | 6.5 | 86 | NO | YES |
CVE-2023-31419HIGH A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service. | Oct 26, 2023 | 7.5 | 57 | NO | NO |
CVE-2021-22146HIGH All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no perm | Jul 21, 2021 | 7.5 | 50 | NO | YES |
CVE-2026-49090MEDIUM Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially craf | Jul 1, 2026 | 6.5 | 32 | NO | NO |
CVE-2026-56148MEDIUM Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query t | Jul 1, 2026 | 6.5 | 32 | NO | NO |
CVE-2015-5377CRITICAL Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-325 | Mar 6, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-63263MEDIUM Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially | Jul 22, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-63144MEDIUM Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with | Jul 21, 2026 | 6.5 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (56 CVEs).
CISA KEV
2 CVEs
3.6% of CVEs· 98th percentile
Metasploit
3 CVEs
5.4% of CVEs· 97th percentile
Nuclei
3 CVEs
5.4% of CVEs· 97th percentile
ExploitDB
4 CVEs
7.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (56 CVEs).
Media Mentions
Signals from CVEs in this product scope (56 CVEs).
Top CNAs Publishing CVEs For Elasticsearch
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.13.3 | 1 | 7.5 | 27.8% | 0 | 1 |
| 6.5.1 | 1 | 5.9 | 1.4% | 0 | 0 |
| 6.5.0 | 1 | 5.9 | 1.4% | 0 | 0 |
| 6.0.0 | 1 | 6.5 | 0.7% | 0 | 0 |