Impact
The vulnerability is a missing authorization flaw (CWE-862) in the custom inference service of Elastic Elasticsearch that can allow a user with only inference execution privileges to cause outbound inference traffic to be redirected to an arbitrary destination. By doing so, the attacker can obtain administrator‑provisioned credentials that are normally protected. The impact is the disclosure of privileged credentials and the potential to abuse inference traffic for malicious purposes. While the flaw only permits information disclosure, the exposed credentials create a broader attack surface for subsequent escalation.
Affected Systems
The affected product is Elastic:Elasticsearch. Specific affected versions were not listed in the CVE data, so the exact vulnerable releases are not identified. Organizations running any public-facing Elasticsearch node that uses the custom inference service should verify against the latest Elasticsearch security updates provided by Elastic.
Risk and Exploitability
The CVSS score of 5.4 places the vulnerability in the medium risk range. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, indicating no known active exploitation. The likely attack requires the attacker to possess inference execution privileges, which may be limited to certain users, but compromised or weakly protected accounts could satisfy this requirement. In practice, the acceptability of exploitation depends on the presence of such accounts and on network controls that limit outbound destinations. Overall, the risk is moderate; however, the exposure of credentials elevates the potential for downstream attacks.
OpenCVE Enrichment