Incorrect authorization in Elasticsearch - CVE-2026-56144

 

Incorrect authorization in Elasticsearch - CVE-2026-56144

Published: July 22, 2026


Vulnerability identifier: #VU139148
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56144
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the ingest simulation feature when simulating ingest pipelines against indices with restricted access. A remote user can target indices they are not authorized to access directly to disclose sensitive information.

This can expose ingest pipeline output and index mapping metadata for indices with restricted access when deployments have configured ingest pipelines and users with differing levels of index privileges.


Affected software

Elasticsearch

How to mitigate CVE-2026-56144

Install security update from vendor's website.

Elasticsearch - addressed in versions 8.19.18, 9.3.7, 9.4.4

External References

Related Security Bulletins