Skip to content
COOEY

FAIL › dossier

Elasticsearch

PRODUCT

· dossier confidence 50%

Elasticsearch is a leading open-source search and analytics platform that has suffered from critical remote code execution vulnerabilities in its scripting engines, which were exploited in the wild and listed in CISA's KEV catalog, indicating a pattern of insufficient sandboxing and dynamic code execution controls.

PROFILE
Categorysearch engine / data analytics platformWhat they doElasticsearch is an open-source, distributed search and analytics engine used for building search, analytics, and application monitoring solutions.
SECURITY POSTURE

Elasticsearch has a history of critical remote code execution vulnerabilities in its scripting engines, which were exploited in the wild and listed in CISA's KEV catalog, indicating a pattern of insufficient sandboxing and dynamic code execution controls.

Notable failures
  • CVE-2015-1427 Groovy sandbox bypass RCE
  • CVE-2014-3120 MVEL/Java dynamic scripting RCE
Patterns: repeated unpatched edge-device RCEs; insufficient sandboxing for dynamic scripting engines
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2015-1427 high Elasticsearch's Groovy scripting engine allowed remote attackers to bypass sandbox protections and execute arbitrary shell commands.
2022-03-25 CVE-2014-3120 high Elasticsearch's dynamic scripting feature allowed remote attackers to execute arbitrary MVEL and Java code, a flaw listed in CISA's KEV catalog.
Open questions: current patch status for CVE-2014-3120 and CVE-2015-1427 · whether Elasticsearch has implemented additional sandboxing controls for dynamic scripting engines
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 03:58:12.535100+00:00