Insufficient Authorization in Elasticsearch Affects Data Security
CVE-2026-56144

5.3MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-56144?

Elasticsearch is vulnerable due to improper authorization mechanisms in its ingest simulation feature. This allows an authenticated user with limited index privileges to exploit these insufficient controls. By targeting restricted indices, the user can initiate configured ingest pipelines, leading to potential exposure of sensitive data processed by these pipelines. Moreover, this exploit enables unauthorized retrieval of index mapping metadata, amplifying security risks for affected systems.

Affected Version(s)

Elasticsearch 9.4.0 <= 9.4.3

Elasticsearch 9.0.0 <= 9.3.6

Elasticsearch 8.12.0 <= 8.19.17

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.