SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78605

MEDIUM · CVSS 5.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to HTTP Request Smuggling due to inconsistent interpretation of HTTP requests, which can result in unauthorized information disclosure. Under certain proxy configurations, an attacker could exploit this vulnerability to access sensitive data meant for other authenticated users. Organizations using Elasticsearch, particularly those with complex proxy setups, should prioritize addressing this issue to mitigate potential data breaches.

CVE
CVE-2026-78605
Severity
MEDIUM
CVSS
5.9
EPSS
0.21%

Original NVD Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.

Related CVEs

Other vulnerabilities affecting the same vendor(s)