CVE-2024-12539: Elastic Elasticsearch

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Affected products

  • Elastic Elasticsearch: from 8.16.0, before 8.16.2 (fixed in 8.16.2)

Published 2024-12-17. Last modified 2026-06-17.