CVE-2026-4799

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
31/03/2026
Last modified:
03/04/2026

Description

In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:search-guard:flx:*:*:*:*:*:*:*:* 4.1.0 (excluding)