Impact
An authorization bypass flaw (CWE‑639) exists in Elasticsearch’s handling of cross‑cluster search requests via the Remote Cluster Security 2.0 model. The flaw allows an attacker holding an API key that is permitted to search a specific index to craft a request in which the identifying attribute used for authorization differs from the attribute that determines the actual target shard. As a result, the request is authorized against a legitimate index while accessing a different, unauthorized index, potentially exposing that index’s documents, field mappings, and metadata. In some scenarios the attacker can also alter retention‑lease state on the unauthorized index.
Affected Systems
Elastic: Elasticsearch is affected. The CVE does not list specific affected releases or patch numbers, so the risk applies to any Elasticsearch deployment that uses the Remote Cluster Security 2.0 model for cross‑cluster search.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is unclear. The likely attack vector involves an attacker leveraging an existing RCS 2.0 authorized API key to submit a crafted request; once authorized, the impact is full data disclosure and limited write capability on a target index.
OpenCVE Enrichment