What is CVE-2026-56144?
CVE-2026-56144 is an Incorrect Authorization vulnerability in Elasticsearch that allows an authenticated user with limited index privileges to bypass authorization controls via the ingest simulation feature. It can impact unauthorized indices' configurations. Mitigation involves upgrading Elasticsearch and restricting ingest simulation permissions.
Azərbaycanca: CVE-2026-56144 Elasticsearch-də səlahiyyət yoxlaması zəifliyidir. Bu, məhdud indeks icazələri olan autentifikasiya olunmuş istifadəçiyə `ingest simulation` funksiyası vasitəsilə icazəsiz indekslərə təsir etməyə imkan verir. Dərhal Elasticsearch-i ən son versiyaya yeniləmək və `ingest simulation` əməliyyatlarını məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which Elasticsearch feature is exploited through CVE-2026-56144?
The vulnerability is exploited via the ingest simulation feature.
What are the recommended mitigation measures for CVE-2026-56144?
Recommended mitigations include upgrading Elasticsearch and restricting ingest simulation permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.