Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-56144'

View all threats tagged with 'cve-2026-56144'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-56144

Threats Tagged 'cve-2026-56144'

Click on any threat for detailed analysis and mitigation recommendations

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient… (CVE-2026-56144)CVE-2026-56144
0

CVE-2026-56144 is an incorrect authorization vulnerability in Elasticsearch's ingest simulation feature. An authenticated user with limited index privileges can exploit insufficient authorization controls to cause ingest pipelines of unauthorized indices to execute and return output. This may disclose data processed or enriched by those pipelines. The vulnerability also allows retrieval of index mapping metadata for unauthorized indices. No patch or remediation information is currently provided. The vulnerability has a medium severity rating and no known exploits in the wild.

Join the discussion
CVE-2026-56144: CWE-863 Incorrect Authorization in Elastic ElasticsearchCVE-2026-56144
0

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest pipelines to execute and return their output, potentially disclosing data processed or enriched by those pipelines. Additionally, the same feature can be used to retrieve index mapping metadata for indices the user are not authorized to access directly.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-56144
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses