Threats Tagged 'cve-2026-56144'
View all threats tagged with 'cve-2026-56144'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-56144'
Click on any threat for detailed analysis and mitigation recommendations
Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient… (CVE-2026-56144)CVE-2026-56144 0 CVE-2026-56144 is an incorrect authorization vulnerability in Elasticsearch's ingest simulation feature. An authenticated user with limited index privileges can exploit insufficient authorization controls to cause ingest pipelines of unauthorized indices to execute and return output. This may disclose data processed or enriched by those pipelines. The vulnerability also allows retrieval of index mapping metadata for unauthorized indices. No patch or remediation information is currently provided. The vulnerability has a medium severity rating and no known exploits in the wild. Join the discussion | GCVE Database | 07/21/2026, 21:32:40 UTC Added: 07/22/2026, 00:11:22 UTC |
CVE-2026-56144: CWE-863 Incorrect Authorization in Elastic ElasticsearchCVE-2026-56144 0 Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest pipelines to execute and return their output, potentially disclosing data processed or enriched by those pipelines. Additionally, the same feature can be used to retrieve index mapping metadata for indices the user are not authorized to access directly. Join the discussion | CVE Database V5 | 07/21/2026, 19:49:43 UTC Added: 07/21/2026, 20:20:53 UTC |
Showing 1 to 2 of 2 results