Back to Database
Status published
Medium
CVE-2025-12149
Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents
Vulnerability Description
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12149
Credits & Attribution
No credits recorded in the NVD database.
References
More from floragunn
View All →CVE-2025-13653
Unauthorized access to documents in data streams with specially crafted requests
Medium
4.3
CVE-2025-12148
Unauthorized access to fields protected by Field Masking (FM) for fields of type IP
Medium
6
CVE-2025-12147
Unauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an object
Medium
6
CVE-2019-13423
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12...
High
8.8
CVE-2019-13422
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12...
Medium
6.1
Affected Vendor
floragunn
View all reports →Affected Software
Search Guard FLX
Vulnerable Versions:
1.0.0
Timeline
Official Publish:
November 14th, 2025
Last Modified:
November 14th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
MITRE ATT&CK TTPs
T1213
Data from Information Repositories
Collection
T1005
Data from Local System
Collection
T1552
Unsecured Credentials
Credential Access
T1041
Exfiltration Over C2 Channel
Exfiltration
T1190
Exploit Public-Facing Application
Initial Access
T1078
Valid Accounts
Persistence
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1021
Remote Services
Lateral Movement
T1098
Account Manipulation
Defense Evasion