Executive brief
Elasticsearch is a search and analytics engine used to store and process large volumes of data. A security flaw in its 'ingest simulation' feature allows users with limited access to view sensitive information or metadata from data collections (indices) they are not supposed to see. This could lead to the unauthorized disclosure of internal data structures or information processed by the system's data pipelines.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the Elasticsearch ingest simulation feature. Authenticated users with limited index privileges can exploit insufficient authorization controls to target indices they are not authorized to access directly. By doing so, an attacker can trigger the execution of configured ingest pipelines and view their output, potentially disclosing enriched or processed data. Additionally, the flaw allows for the retrieval of index mapping metadata for restricted indices. The attack requires network access and valid (though limited) credentials, with a high complexity due to the specific configuration requirements of ingest pipelines. The issue is resolved in versions 8.19.18, 9.3.7, and 9.4.4; version 9.5.0 and later are unaffected.
Affected products
- Elastic Elasticsearch 8.12.0 to 8.19.17, 9.0.0 to 9.3.6, 9.4.0 to 9.4.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched: Fixed in 8.19.18, 9.3.7, 9.4.4, and 9.5.0