SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-56144

MEDIUM · CVSS 5.3 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Elasticsearch contains an incorrect authorization vulnerability that allows authenticated users with limited index privileges to exploit insufficient controls in the ingest simulation feature. This can lead to unauthorized access to sensitive data processed by ingest pipelines and retrieval of index mapping metadata for indices beyond their access rights. Organizations using Elasticsearch should prioritize addressing this vulnerability to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56144
Severity
MEDIUM
CVSS
5.3
EPSS
0.23%

Original NVD Description

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest pipelines to execute and return their output, potentially disclosing data processed or enriched by those pipelines. Additionally, the same feature can be used to retrieve index mapping metadata for indices the user are not authorized to access directly.

Related CVEs

Other vulnerabilities affecting the same vendor(s)