CVE-2026-4799: Search-Guard Flx
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
Affected products
- Search-Guard Flx: before 4.1.0 (fixed in 4.1.0)
Published 2026-03-31. Last modified 2026-07-24.