CVE-2025-13653: Floragunn Search Guard Flx
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.
Affected products
- Floragunn Search Guard Flx: from 3.1.0, up to and including 4.0.0
Published 2025-12-01. Last modified 2026-06-17.