In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams. | |
| Title | Some management operations on data streams are not properly restricted when user does not have the necessary privileges | |
| Weaknesses | CWE-285 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: floragunn
Published:
Updated: 2026-03-31T17:23:23.853Z
Reserved: 2026-03-25T13:44:35.684Z
Link: CVE-2026-4818
Updated: 2026-03-31T17:23:18.597Z
Status : Received
Published: 2026-03-31T16:16:34.580
Modified: 2026-03-31T16:16:34.580
Link: CVE-2026-4818
No data.