← Vulnerability feed

Vulnerability record · CVE-2015-1427 · published 17 February 2015

CVE-2015-1427: Elasticsearch Groovy scripting engine sandbox escape RCE

Elastic · Elasticsearch

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbitrary shell commands. Because the flaw is reachable over the network without credentials, any exposed Elasticsearch instance running an affected version is at risk of full compromise.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 100% · top 0.1%
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
17References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8, KEV listing, and near-maximum EPSS probability.

What it is

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbitrary shell commands. Because the flaw is reachable over the network without credentials, any exposed Elasticsearch instance running an affected version is at risk of full compromise.

Impact

An attacker gains remote code execution with the privileges of the Elasticsearch process, allowing arbitrary shell commands, data theft, and host takeover.

Attack surface

Reached over the network via the Elasticsearch HTTP API by submitting a crafted Groovy script; the CVSS vector shows no privileges or user interaction required.

Exploitation

Listed in CISA KEV since 2022-03-25 with a required action to apply vendor updates, and EPSS probability is 0.99906 (99.966th percentile); references include an exploit-tagged Packet Storm entry. No ransomware campaign use is documented.

What to do

  • Upgrade to Elasticsearch 1.3.8 or 1.4.3 (or later) per the vendor advisory.
  • Disable dynamic Groovy scripting (script.disable_dynamic: true) where the version supports it.
  • Restrict network access to the Elasticsearch HTTP and transport ports; do not expose them to untrusted networks.
  • Enable authentication and authorization if the deployment supports it, and monitor for unauthorized script submissions.
  • Apply the Red Hat errata (RHSA-2017:0868) for affected Red Hat products.

Detection

  • Search Elasticsearch logs for Groovy script submissions containing Runtime, exec, ProcessBuilder, or shell metacharacters.
  • Monitor for outbound connections or child processes spawned by the Elasticsearch service.
  • Alert on requests to scripting endpoints from unexpected source IPs or with anomalous payload sizes.
  • Audit exposed Elasticsearch instances for versions below 1.3.8 or 1.4.3.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-1427 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/ PatchVendor Advisory
http://www.securityfocus.com/archive/1/534689/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/72585 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:0868 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/100850 Third Party AdvisoryVDB Entry
https://www.elastic.co/community/security/ Not ApplicableVendor Advisory
http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/ PatchVendor Advisory
http://www.securityfocus.com/archive/1/534689/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/72585 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:0868 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/100850 Third Party AdvisoryVDB Entry
https://www.elastic.co/community/security/ Not ApplicableVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1427 US Government Resource

Track CVE-2015-1427 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4437Apache Shiro hardcoded remember-me cipher key enables code executionApache Shiro before 1.2.5 uses a default cipher key for the "remember me" feature when no key is configured, allowing attackers to forge or decrypt r…KEVEPSS 93%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed8.1CVE-2014-3120Elasticsearch dynamic scripting allows remote code executionThe default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expres…KEVEPSS 89%analysed9.8CVE-2018-1270Spring Framework STOMP over WebSocket broker remote code executionSpring Framework versions 5.0 before 5.0.5 and 4.3 before 4.3.15 (plus older unsupported versions) allow applications to expose STOMP over WebSocket …EPSS 77%analysed9.8CVE-2015-5377Elasticsearch injection vulnerabilityElasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appe…EPSS 14%9.8CVE-2017-5645Apache Log4j 2 socket server deserialization allows remote code executionApache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted ser…EPSS 90%analysed9.6CVE-2025-12543Redhat build of apache camel improper input validation vulnerabilityA flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…EPSS 1.4%9.1CVE-2026-28369Redhat build of apache camel - hawtio http request smuggling vulnerabilityA flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2015-1427), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.