6.5

CVE-2026-4819

Search Guard audit logs can contain under certain conditions user credentials

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Search-guardFlx Version >= 1.0.0 < 4.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.113
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
security@search-guard.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://search-guard.com/cve-advisory/
Vendor Advisory
https://docs.search-guard.com/latest/changelog-searchguard-flx-4_1_0
Release Notes