Skip to content
ElasticCVE-2026-56144

Elasticsearch: improper authorization

Medium5.3CVE-2026-56144 · Published Jul 21, 2026 · updated Aug 26, 2026

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest pipelines to execute and return their output, potentially disclosing data processed or enriched by those pipelines. Additionally, the same feature can be used to retrieve index mapping metadata for indices the user are not authorized to access directly.

Elastic advisory

Affected versions

PackageAffectedFixed in
Elasticsearch
Product
>= 9.4.0, <= 9.4.3No fix yet
>= 9.0.0, <= 9.3.7No fix yet
>= 8.12.0, <= 8.19.18No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Elastic advisories

All Elastic
Advisory
Elastic Kibana: improper authorization
Medium5.0Jul 21
Elastic Kibana: missing authorization
Medium4.3Jul 21
Elasticsearch: denial of service
Medium6.5Jul 21
Elastic Kibana: improper authorization
Medium4.3Jul 21
Elastic Kibana: information disclosure
Medium4.3Jul 21
Elastic Kibana: resource exhaustion
Medium6.5Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.