CVE-2025-12149EPSS p19.1%
CVE-2025-12149CVE-2025-12149
Description
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Scoring
| EPSS | 0.28% probability of exploitation · percentile 19.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |