← Vulnerability feed

Vulnerability record · CVE-2014-3120 · published 28 July 2014

CVE-2014-3120: Elasticsearch dynamic scripting allows remote code execution

Elastic · Elasticsearch

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expressions and Java code. This gives remote attackers a direct path to code execution on any instance left with default settings.

8.1 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 89% · top 0.2% CWE-284 · Improper access control
8.1CVSS 3.1 base score, v2 6.8
89%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
17References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with public exploit code and a very high EPSS score, and it yields remote code execution.

What it is

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expressions and Java code. This gives remote attackers a direct path to code execution on any instance left with default settings.

Impact

An attacker can run arbitrary MVEL expressions and Java code on the Elasticsearch server, leading to full compromise of the host process and its data. The CVSS vector shows high confidentiality and integrity impact with no availability impact.

Attack surface

Reached over the network through the _search endpoint's source parameter; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). The description notes the flaw only violates the vendor's intended security policy if Elasticsearch is not run in its own independent virtual machine.

Exploitation

CISA added this to KEV on 2022-03-25 with a due date of 2022-04-15, and EPSS shows a 30-day probability of 0.88559 (99.766th percentile). Multiple references are tagged Exploit, including Exploit-DB and a Rapid7 Metasploit module, so public exploit code exists.

What to do

  • Upgrade Elasticsearch to 1.2 or later, where dynamic scripting is disabled by default.
  • If upgrading is not immediately possible, disable dynamic scripting in the configuration.
  • Restrict network access to the Elasticsearch HTTP/search port so only trusted hosts can reach it.
  • Run Elasticsearch in an isolated environment or dedicated VM as the vendor intended.
  • Review the cluster for unauthorized changes or unexpected processes.

Detection

  • Monitor _search requests for a source parameter containing MVEL or Java code.
  • Alert on Elasticsearch process spawning unexpected child processes or outbound connections.
  • Audit Elasticsearch configuration for dynamic scripting being enabled.
  • Check logs for anomalous search queries or errors tied to script execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-3120 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Elasticsearch Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-3120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-1427Elasticsearch Groovy scripting engine sandbox escape RCEThe Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbit…KEVEPSS 100%analysed9.8CVE-2015-5377Elasticsearch injection vulnerabilityElasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appe…EPSS 14%8.8CVE-2026-72649Elasticsearch deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (C…EPSS 0.92%8.8CVE-2026-72642Elasticsearch vulnerabilityThe native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory ad…EPSS 0.60%8.8CVE-2021-37937Elasticsearch improper privilege management vulnerabilityAn issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is poss…EPSS 0.71%8.8CVE-2020-7014Elasticsearch improper privilege management vulnerabilityThe fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl…EPSS 1.5%8.8CVE-2020-7009Elasticsearch improper privilege management vulnerabilityElasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. …EPSS 1.6%8.8CVE-2018-3831Elasticsearch information exposure vulnerabilityElasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2014-3120), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.