Vulnerabilities > Elastic > Elasticsearch > 8.16.0

DATE CVE VULNERABILITY TITLE RISK
2024-12-17 CVE-2024-12539 Incorrect Authorization vulnerability in Elastic Elasticsearch 8.16.0/8.16.1
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.
network
low complexity
elastic CWE-863
6.5