PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4799 floragunn CVE debrief

CVE-2026-4799 is a medium-severity vulnerability in Search Guard FLX up to version 4.0.1, allowing attackers to redirect users to untrusted URLs through specially crafted requests. This issue has been addressed in version 4.1.0 of Search Guard FLX. The vulnerability, classified as CWE-601, poses a risk of redirecting users to malicious sites. Users of Search Guard FLX up to version 4.0.1 should be aware of this vulnerability and take steps to mitigate it, including upgrading to version 4.1.0 or applying compensating controls.

Vendor
floragunn
Product
Search Guard FLX
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-31
Original CVE updated
2026-07-24
Advisory published
2026-03-31
Advisory updated
2026-07-24

Who should care

Users of Search Guard FLX up to version 4.0.1 should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to version 4.1.0 or applying compensating controls to prevent exploitation. Security teams and vulnerability management teams should prioritize addressing this vulnerability, as it could be used to redirect users to malicious sites.

Technical summary

The vulnerability in Search Guard FLX allows attackers to redirect users to untrusted URLs through specially crafted requests. This is achieved by exploiting the lack of proper validation in the affected versions of Search Guard FLX. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 4.3, indicating a medium severity level. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N. The vulnerability affects Search Guard FLX up to version 4.0.1 and has been addressed in version 4.1.0.

Defensive priority

Medium priority should be given to addressing this vulnerability, as it could be used to redirect users to malicious sites. However, the actual priority may vary depending on the specific deployment and exposure of Search Guard FLX in the environment.

Recommended defensive actions

  • Upgrade to Search Guard FLX version 4.1.0 or later
  • Implement compensating controls to detect and prevent suspicious redirects
  • Monitor user activity for signs of exploitation
  • Review and update incident response plans to address potential exploitation of this vulnerability
  • Conduct a thorough review of affected Search Guard FLX deployments to identify potential exposure
  • Verify the integrity of Search Guard FLX configurations to prevent unauthorized changes
  • Track and analyze network logs for potential exploitation attempts

Evidence notes

The CVE record for CVE-2026-4799 was published on 2026-03-31T15:16:21.137Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The vulnerability is described as CWE-601. Evidence from the CVE record and NVD entry indicates that Search Guard FLX up to version 4.0.1 is affected. However, the exact scope of affected deployments and potential exposure is not detailed in the CVE record or NVD entry. Defenders should verify the affected versions and configurations in their environments.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T15:16:21.137Z and has not been modified since then. The NVD entry is currently Analyzed.