Incorrect authorization in Elasticsearch - CVE-2026-56144
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the ingest simulation feature when simulating ingest pipelines against indices with restricted access. A remote user can target indices they are not authorized to access directly to disclose sensitive information.
This can expose ingest pipeline output and index mapping metadata for indices with restricted access when deployments have configured ingest pipelines and users with differing levels of index privileges.