Skip to main content

Port Details

Port
9200
Transport
TCP
Service
Elasticsearch
IANA service name
wap-wsp
Range
User port (1024-49151)
Related ports
9300

Security Exposure

Elastic's networking documentation warns never to expose an unprotected node to the public internet, because anyone could then download, modify, or delete data in the cluster. Security auto-configuration adds http.host: 0.0.0.0 to elasticsearch.yml, so HTTP listens on all interfaces unless changed. CISA added two older Elasticsearch remote code execution flaws, CVE-2014-3120 and CVE-2015-1427, to its Known Exploited Vulnerabilities catalog in March 2022.

Hardening

  • +Keep network.host on loopback or private interfaces, and firewall 9200 and 9300 from untrusted networks.
  • +Use the security auto-configuration introduced in Elasticsearch 8.0, which generates TLS certificates for the HTTP and transport layers and sets a password for the elastic user.
  • +Create role-based users or API keys for applications instead of sharing the superuser.
  • +Upgrade Elasticsearch releases that are out of support and apply Elastic security updates.

Monitoring

Enable Elasticsearch audit logging, which records authentication attempts and authorization decisions, and alert on authentication failures, index deletions, and requests from addresses outside the application tier.

Elasticsearch Vulnerabilities

2 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2015-1427
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
-9.899.9%KEV2015-02-17
CVE-2014-3120
Elasticsearch Remote Code Execution Vulnerability
-8.188.6%KEV2014-07-28

Tools for Auditing and Monitoring Elasticsearch

Elastic Security

Free / Commercial
SIEM Tools

SIEM and XDR built on the Elastic Stack with open detection rules and endpoint integration.

LicenseElastic-2.0 (Security solution, detection rules); AGPL-3.0-only OR SSPL-1.0 OR Elastic-2.0 (Elasticsearch, Kibana core)
PlatformWeb, Linux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is port 9200 used for?→

It is the default Elasticsearch HTTP REST API port. Port 9300 carries traffic between cluster nodes.

Should port 9200 be open to the internet?→

No. Elastic's documentation says an unprotected node on the public internet lets anyone read, change, or delete cluster data.

Is Elasticsearch secure by default?→

From version 8.0, the first startup generates TLS certificates for the HTTP and transport layers and sets a password for the elastic user.

Which vulnerabilities affect the service on port 9200?→

This database lists 2 CVEs related to Elasticsearch, 2 of them confirmed as exploited by CISA. Examples: CVE-2015-1427, CVE-2014-3120.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9200 is not guaranteed to be Elasticsearch. Exploited-in-the-wild data from the CISA KEV catalog (CC0).