🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-56145 is a vulnerability in Elasticsearch that allows an attacker to consume excessive system resources, potentially causing a Denial of Service (DoS) condition. This affects Azure-hosted environments where Elasticsearch is in use. If exploited, legitimate users and dependent services could be rendered unavailable, impacting business continuity.

Security Architect’s Take: Identify all Azure workloads running Elasticsearch and apply any available patches or mitigations from both Microsoft and Elastic immediately. In the interim, consider enforcing strict network access controls and rate limiting to reduce the attack surface for unauthenticated or low-privilege resource exhaustion attempts.

Original advisory: CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service