CVE-2025-12149 – Unauthorized access to documents protected by Document-Level Security (DLS), when Signal’s watches include a search query involving protected documents
CVE ID : CVE-2025-12149
Published : Nov. 14, 2025, 2:15 p.m. | 44 minutes ago
Description : In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal’s watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…