search-guard has 3 CVEs on record. The busiest recent month was March 2026 with 3. The median CVSS is 4.9 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.9
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-4818Medium· 6.8In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.37CVE-2026-4819Medium· 4.9In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.27CVE-2026-4799Medium· 4.3In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.24
search-guard vulnerabilities
CVEs affecting search-guard, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-4819Medium· 4.9In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
▾ Sunlitsearch-guard · flxEPSS 0.21%via NVD
CVE-2026-4818Medium· 6.8In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
▾ Sunlitsearch-guard · flxEPSS 0.19%via NVD
CVE-2026-4799Medium· 4.3In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
▾ Sunlitsearch-guard · flxEPSS 0.18%via NVD