Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY89 SECURITY RECORDS

Elastic

elasticsearch

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Elasticsearch. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-103009 6 Oct 2026 Elasticsearch: 8.13.0 ≤ 8.19.22, 9.0.0 ≤ 9.4.7, 9.5.0 ≤ 9.5.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-103008 6 Oct 2026 Elasticsearch: 8.12.0 ≤ 8.19.22, 9.0.0 ≤ 9.4.7, 9.5.0 ≤ 9.5.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-103007 6 Oct 2026 Elasticsearch: 8.16.0 ≤ 8.19.21, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-103006 6 Oct 2026 Elasticsearch: 8.0.0 ≤ 8.19.20, 9.0.0 ≤ 9.4.5, 9.5.0 ≤ 9.5.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-103005 6 Oct 2026 Elasticsearch: 8.12.0 ≤ 8.19.22, 9.0.0 ≤ 9.3.8, 9.4.0 ≤ 9.4.7, 9.5.0 ≤ 9.5.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-102411 6 Oct 2026 Elasticsearch: 8.0.0 ≤ 8.19.22, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-102409 6 Oct 2026 Elasticsearch: 9.2.0 ≤ 9.2.8, 9.3.0 ≤ 9.3.8, 9.4.0 ≤ 9.4.7, 9.5.0 ≤ 9.5.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-102408 6 Oct 2026 Elasticsearch: 8.19.0 ≤ 8.19.21, 9.1.0 ≤ 9.3.8, 9.4.0 ≤ 9.4.7, 9.5.0 ≤ 9.5.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-102407 6 Oct 2026 Elasticsearch: 7.17.5 ≤ 7.17.29, 8.2.2 ≤ 8.19.18, 9.0.0 ≤ 9.3.7, 9.4.0 ≤ 9.4.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-102404 6 Oct 2026 Elasticsearch: 8.0.0 ≤ 8.19.22, 9.0.0 ≤ 9.4.7, 9.5.0 ≤ 9.5.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-94408 26 Sep 2026 Elasticsearch: 8.0.0 ≤ 8.19.21, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-94397 26 Sep 2026 Elasticsearch: 8.0.0 ≤ 8.19.21, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-94396 26 Sep 2026 Elasticsearch: 9.2.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-94399 26 Sep 2026 Elasticsearch: 8.0.0 ≤ 8.19.21, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-94398 26 Sep 2026 Elasticsearch: 8.12.0 ≤ 8.19.21, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-82300 26 Sep 2026 Elasticsearch: 8.0.0 ≤ 8.19.21, 9.0.0 ≤ 9.4.6, 9.5.0 ≤ 9.5.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-82294 26 Sep 2026 Elasticsearch: 8.0.0 ≤ 8.19.20, 9.0.0 ≤ 9.4.5, 9.5.0 ≤ 9.5.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-78607 1 Sep 2026 8.0.0 ≤ 8.19.18; 9.0.0 ≤ 9.3.7; 9.4.0 ≤ 9.4.3; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-78605 1 Sep 2026 8.18.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72649 1 Sep 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56143 1 Sep 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.2.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72636 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72642 13 Aug 2026 8.19.0 ≤ 8.19.19; 9.4.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72639 13 Aug 2026 8.19.0 ≤ 8.19.19; 9.3.0 ≤ 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72638 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72647 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72645 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72656 13 Aug 2026 8.11.0 ≤ 8.17.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72679 13 Aug 2026 8.19.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72678 13 Aug 2026 8.19.0 ≤ 8.19.19; 9.4.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72687 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72686 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4; 9.5.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72685 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72684 13 Aug 2026 8.0.0 ≤ 8.19.19; 9.0.0 ≤ 9.4.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-72683 13 Aug 2026 5.0.0 ≤ 8.19.18; 9.3.0 ≤ 9.3.7; 9.4.0 ≤ 9.4.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-63263 21 Jul 2026 9.4.0 ≤ 9.4.3; 9.0.0 ≤ 9.3.7; 8.0.0 ≤ 8.19.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-63144 21 Jul 2026 9.4.0 ≤ 9.4.3; 9.3.0 ≤ 9.3.7; 8.19.0 ≤ 8.19.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-63140 21 Jul 2026 9.0.0 ≤ 9.3.7; 9.4.0 ≤ 9.4.3; 8.0.0 ≤ 8.19.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-63136 21 Jul 2026 8.0.0 ≤ 8.19.14; 9.3.0 ≤ 9.3.3; 9.0.0 ≤ 9.2.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56145 21 Jul 2026 9.4.0 ≤ 9.4.3; 8.0.0 ≤ 8.19.17; 9.0.0 ≤ 9.3.6 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56144 21 Jul 2026 9.4.0 ≤ 9.4.3; 9.0.0 ≤ 9.3.7; 8.12.0 ≤ 8.19.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-49090 1 Jul 2026 8.0.0 ≤ 8.14.3; 7.0.0 ≤ 7.17.23 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56149 1 Jul 2026 9.4.0 ≤ 9.4.2; 9.0.0 ≤ 9.3.5; 8.0.0 ≤ 8.19.16 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56148 1 Jul 2026 9.4.0 ≤ 9.4.2; 9.0.0 ≤ 9.3.5; 8.0.0 ≤ 8.19.16 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-68390 18 Dec 2025 7.0.0 ≤ 7.17.29; 8.0.0 ≤ 8.19.7; 9.0.0 ≤ 9.1.7; 9.2.0 ≤ 9.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-68384 18 Dec 2025 Elasticsearch: 7.0.0 ≤ 7.17.29, 8.0.0 ≤ 8.19.8, 9.0.0 ≤ 9.1.8, 9.2.0 ≤ 9.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-37731 15 Dec 2025 Elasticsearch: 7.0.0 ≤ 7.17.29, 8.0.0 ≤ 8.19.7, 9.0.0 ≤ 9.1.7, 9.2.0 ≤ 9.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-37727 10 Oct 2025 7.0.0 ≤ 7.17.29; 8.0.0 ≤ 8.18.7; 8.19.0 ≤ 8.19.4; 9.0.0 ≤ 9.0.7; 9.1.0 ≤ 9.1.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-52979 1 May 2025 7.17.0 < 7.17.25; 8.0.0 < 8.16.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-52981 8 Apr 2025 7.17.0 ≤ 7.17.23; 8.0 ≤ 8.15.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.