CVE-2026-4819

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
Configurations

Configuration 1 (hide)

cpe:2.3:a:search-guard:flx:*:*:*:*:*:*:*:*

History

03 Apr 2026, 13:49

Type Values Removed Values Added
First Time Search-guard
Search-guard flx
CPE cpe:2.3:a:search-guard:flx:*:*:*:*:*:*:*:*
References () https://docs.search-guard.com/latest/changelog-searchguard-flx-4_1_0 - () https://docs.search-guard.com/latest/changelog-searchguard-flx-4_1_0 - Release Notes
References () https://search-guard.com/cve-advisory/ - () https://search-guard.com/cve-advisory/ - Vendor Advisory

31 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 16:16

Updated : 2026-04-03 13:49


NVD link : CVE-2026-4819

Mitre link : CVE-2026-4819

CVE.ORG link : CVE-2026-4819


JSON object : View

Products Affected

search-guard

  • flx
CWE
CWE-522

Insufficiently Protected Credentials

CWE-532

Insertion of Sensitive Information into Log File