CVE-2026-4819

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
31/03/2026
Last modified:
03/04/2026

Description

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:search-guard:flx:*:*:*:*:*:*:*:* 1.0.0 (including) 4.1.0 (excluding)