Junglewise Threat Intelligence

CVE-2026-4799: floragunn Search Guard FLX open redirect in Kibana Plugin

CVE-2026-4799 · Severity: medium · CVSS 4.3 · Published 2026-03-31

Technologies: Floragunn Search Guard FLX, Search-Guard Flx. Vendors: Floragunn, Search-Guard.

Executive brief

Search Guard FLX, a security plugin for Elasticsearch and Kibana, is vulnerable to an open redirect flaw. An attacker can send a specially crafted link to a user that, when clicked, redirects them from a trusted corporate domain to a malicious website. This technique is commonly used in phishing campaigns to steal user credentials or deliver malware by exploiting the user's trust in the original site.

Technical details

An open redirect vulnerability (CWE-601) exists in the Search Guard Kibana Plugin component of Search Guard FLX. The flaw is rooted in insufficient validation of user-supplied input used in redirection parameters. A remote, unauthenticated attacker can exploit this by tricking a victim into clicking a specially crafted URL. Successful exploitation allows the attacker to redirect the victim to an arbitrary external domain, facilitating phishing or social engineering attacks. The vulnerability is addressed in Search Guard FLX version 4.1.0.

Affected products

  • floragunn Search Guard FLX 1.0.0 - 4.0.1

Timeline

  • 2026-03-25: patched: Version 4.1.0 released fixing the issue.
  • 2026-03-31: disclosed: Initial advisory publication.
  • 2026-03-31: advisory: NVD entry published.

References

Related threats