Vulnerability record · CVE-2015-1427 · published 17 February 2015
CVE-2015-1427: Elasticsearch Groovy scripting engine sandbox escape RCE
Elastic · Elasticsearch
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbitrary shell commands. Because the flaw is reachable over the network without credentials, any exposed Elasticsearch instance running an affected version is at risk of full compromise.
Description
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8, KEV listing, and near-maximum EPSS probability.
What it is
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbitrary shell commands. Because the flaw is reachable over the network without credentials, any exposed Elasticsearch instance running an affected version is at risk of full compromise.
Impact
An attacker gains remote code execution with the privileges of the Elasticsearch process, allowing arbitrary shell commands, data theft, and host takeover.
Attack surface
Reached over the network via the Elasticsearch HTTP API by submitting a crafted Groovy script; the CVSS vector shows no privileges or user interaction required.
Exploitation
Listed in CISA KEV since 2022-03-25 with a required action to apply vendor updates, and EPSS probability is 0.99906 (99.966th percentile); references include an exploit-tagged Packet Storm entry. No ransomware campaign use is documented.
What to do
- Upgrade to Elasticsearch 1.3.8 or 1.4.3 (or later) per the vendor advisory.
- Disable dynamic Groovy scripting (script.disable_dynamic: true) where the version supports it.
- Restrict network access to the Elasticsearch HTTP and transport ports; do not expose them to untrusted networks.
- Enable authentication and authorization if the deployment supports it, and monitor for unauthorized script submissions.
- Apply the Red Hat errata (RHSA-2017:0868) for affected Red Hat products.
Detection
- Search Elasticsearch logs for Groovy script submissions containing Runtime, exec, ProcessBuilder, or shell metacharacters.
- Monitor for outbound connections or child processes spawned by the Elasticsearch service.
- Alert on requests to scripting endpoints from unexpected source IPs or with anomalous payload sizes.
- Audit exposed Elasticsearch instances for versions below 1.3.8 or 1.4.3.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1427 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1427 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1427), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.