A vulnerability labeled as critical has been found in Elastic Elasticsearch up to 8.19.18/9.3.7/9.4.3. The affected element is an unknown function of the component Query Parsing. The manipulation results in reachable assertion.

This vulnerability is known as CVE-2026-63140. It is possible to launch the attack remotely. No exploit is available.