PT-2026-85127 · Bitnami · Elasticsearch

Published

2026-09-03

·

Updated

2026-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-ELASTICSEARCH-2026-78607

Affected Products

Elasticsearch