Elasticsearch reported this major-impact incident on its official status page on Aug 5, 2026, 22:59 UTC. It was resolved after 6d 10h.
Right now Elasticsearch is operational. Live Elasticsearch status →
Elasticsearch 9.5.1 has been released and contains the fix for this issue. Customers running 9.5.0 should upgrade to 9.5.1. At this time we are considering this issue resolved and will be providing no further updates.
A patch release containing the fix is in progress and it is expected to be available within the next week. Our recommendation to defer upgrading to 9.5.0 until 9.5.1 is available remains unchanged.
Further investigation confirmed the impact of this issue was limited to boolean queries containing a must, filter, or should clause, along with a must_not clause on unindexed fields. Such queries can return false-positives returning documents that should have been excluded and report higher document counts than expected. We have identified the root cause, a fix is in progress, and we are preparing a patch release. We will provide a further update by 10:00 UTC August 6.
Elasticsearch 9.5.0 contains a defect that can cause searches to return incorrect results for any index or data stream that disables indexing on a queried field . A query that excludes values using a must_not clause may fail to exclude them when the targeted field has doc values enabled but is not indexed for search. Affected searches can return documents that should have been excluded and report higher document counts than expected, and results may vary between runs of the same query. No error is raised, so affected queries appear to succeed. Dashboards, alerting rules, and anything else built on these searches may report inaccurate values. Both the query DSL and ES|QL are affected. Time series (TSDB) data streams are the most likely to be affected, because indexing is disabled by default for these fields. Columnar indices, currently in technical preview, are affected for the same reason. Any index or data stream that disables indexing on a queried field can be affected. This affec
Our 5-minute checks didn't record a change in Elasticsearch's overall status around this incident. Smaller or regional incidents often leave a provider's overall status green.
Overlapping incidents aren't necessarily related.
Elasticsearch reported 23 incidents in the last 90 days, 20 of them major or critical. A typical incident lasted 3h 35m. See Elasticsearch's uptime and incident history