---
id: CVE-2025-12149
title: >-
  In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security
  (DLS) is correctly enforced elsewhere, when the search is triggered from a
  Signals watch, the DLS rule is not enforced, allowing access to all documents
  in the…
summary: >-
  In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security
  (DLS) is correctly enforced elsewhere, when the search is triggered from a
  Signals watch, the DLS rule is not enforced, allowing access to all documents
  in the…
severity: none
cwe:
  - CWE-200
  - CWE-863
published: '2025-11-14'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12149'
references:
  - url: 'https://docs.search-guard.com/latest/changelog-searchguard-flx-3_1_3'
    label: security@search-guard.com
  - url: 'https://docs.search-guard.com/latest/changelog-searchguard-flx-4_0_0'
    label: security@search-guard.com
  - url: 'https://search-guard.com/cve-advisory/'
    label: security@search-guard.com
tags:
  - nvd
epss: 0.00283
epssPercentile: 0.1902
ingestedAt: '2026-10-07T21:54:15.038Z'
---

## Overview

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
