Insufficient Authorization in Elasticsearch Affects Data Security
CVE-2026-56144
5.3MEDIUM
What is CVE-2026-56144?
Elasticsearch is vulnerable due to improper authorization mechanisms in its ingest simulation feature. This allows an authenticated user with limited index privileges to exploit these insufficient controls. By targeting restricted indices, the user can initiate configured ingest pipelines, leading to potential exposure of sensitive data processed by these pipelines. Moreover, this exploit enables unauthorized retrieval of index mapping metadata, amplifying security risks for affected systems.
Affected Version(s)
Elasticsearch 9.4.0 <= 9.4.3
Elasticsearch 9.0.0 <= 9.3.6
Elasticsearch 8.12.0 <= 8.19.17