Medium severity6.5NVD Advisory· Published Aug 13, 2026· Updated Sep 1, 2026
CVE-2026-72683
CVE-2026-72683
Description
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to submit a request that causes a self-referential data structure to be created. When a specific internal component later processes that structure, the operation recurses without bound and raises a fatal error that is not handled by the surrounding execution path, terminating the affected node process and resulting in a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1News mentions
1- Elasticsearch: Twelve DoS Vulnerabilities Disclosed Together, One High SeverityVypr Intelligence · Aug 13, 2026