this is simply server security... the application happens to be classed as IoT, but this is has nothing to do with the IoT aspects.
If the functionality of your home depends on a privately owned, 3rd-party server, then I'd say it very much highlights the potential risks of IoT devices / applications.
My electricity, gas, water etc all come from 3rd-party providers and work just fine. Probably because they're all heavily regulated.
(FWIW I don't have any IoT devices in my house)
They work just fine because you don't need to log in to your electricity meter to turn your lights on.
The backend component is just as important as the endpoint component. Pretending that IoT is one or the other, but not both is one of the biggest security root causes.
So how would this play out differently if an exposed Elasticsearch cluster was connected to an endpoint different from IoT?
The problem is neither IoT nor ES - whoever built this just didn't bother to implement even basic security.
I bet the server is publicly accessible because the data collection from the IoT devices does a POST directly to the ElasticSearch server.