Port 9200: Elasticsearch HTTP REST API
IANA registers 9200 as wap-wsp (WAP connectionless session service), but the port is best known as the Elasticsearch HTTP API. Elasticsearch binds HTTP to the first free port in 9200-9300 and node-to-node transport to 9300-9400.
Port Details
Security Exposure
Elastic's networking documentation warns never to expose an unprotected node to the public internet, because anyone could then download, modify, or delete data in the cluster. Security auto-configuration adds http.host: 0.0.0.0 to elasticsearch.yml, so HTTP listens on all interfaces unless changed. CISA added two older Elasticsearch remote code execution flaws, CVE-2014-3120 and CVE-2015-1427, to its Known Exploited Vulnerabilities catalog in March 2022.
Hardening
- +Keep network.host on loopback or private interfaces, and firewall 9200 and 9300 from untrusted networks.
- +Use the security auto-configuration introduced in Elasticsearch 8.0, which generates TLS certificates for the HTTP and transport layers and sets a password for the elastic user.
- +Create role-based users or API keys for applications instead of sharing the superuser.
- +Upgrade Elasticsearch releases that are out of support and apply Elastic security updates.
Monitoring
Enable Elasticsearch audit logging, which records authentication attempts and authorization decisions, and alert on authentication failures, index deletions, and requests from addresses outside the application tier.
Elasticsearch Vulnerabilities
2 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2015-1427 | Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability | - | 9.8 | 99.9% | KEV | 2015-02-17 |
| CVE-2014-3120 | Elasticsearch Remote Code Execution Vulnerability | - | 8.1 | 88.6% | KEV | 2014-07-28 |
Tools for Auditing and Monitoring Elasticsearch
Elastic Security
Free / CommercialSIEM and XDR built on the Elastic Stack with open detection rules and endpoint integration.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Related Tool Categories
Data loss prevention, data posture management, and sensitive data discovery and classification platforms.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is port 9200 used for?→
It is the default Elasticsearch HTTP REST API port. Port 9300 carries traffic between cluster nodes.
Should port 9200 be open to the internet?→
No. Elastic's documentation says an unprotected node on the public internet lets anyone read, change, or delete cluster data.
Is Elasticsearch secure by default?→
From version 8.0, the first startup generates TLS certificates for the HTTP and transport layers and sets a password for the elastic user.
Which vulnerabilities affect the service on port 9200?→
This database lists 2 CVEs related to Elasticsearch, 2 of them confirmed as exploited by CISA. Examples: CVE-2015-1427, CVE-2014-3120.
Sources
- IANA Service Name and Port Number Registry (CSV)
- Elastic: Networking settings
- Elastic: Automatic security setup
- NVD: CVE-2015-1427
- NVD: CVE-2014-3120
- Elasticsearch Guide 8.0: Start the Elastic Stack with security enabled
- Elastic Docs: Security event audit logging
- CISA Known Exploited Vulnerabilities Catalog
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9200 is not guaranteed to be Elasticsearch. Exploited-in-the-wild data from the CISA KEV catalog (CC0).