🟠 High | Source: Microsoft Security Response Center
CVE-2026-63136 is a vulnerability in Elasticsearch that allows uncontrolled resource consumption, which can be exploited to cause a Denial of Service (DoS). This affects Azure environments where Elasticsearch is deployed, potentially rendering search and analytics services unavailable. An attacker able to send crafted requests could exhaust system resources, disrupting dependent applications and workloads.
Security Architect’s Take: Review any Azure-hosted Elasticsearch deployments and apply available patches or mitigations from Microsoft and Elastic immediately. Additionally, implement rate limiting and network-level controls to restrict access to Elasticsearch endpoints to trusted sources only, reducing the attack surface.
Original advisory: CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service