An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.12.0"
},
{
"fixed": "8.12.1"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-284"
],
"cna_assigner": "elastic",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23446.json"
}"2026-07-22T02:51:12Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"201606926101981761165198018477399366221",
"68571496898305629436217873761975339552",
"106248183962439458817886600139816741681",
"254487700143949059801556026494769505498",
"87068743167677976748508957386413101640"
]
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/6185ba65d27469afabc9bc951cded6c17c21e3f3",
"id": "CVE-2024-23446-70dad566",
"target": {
"file": "x-pack/plugin/esql/src/main/java/org/elasticsearch/xpack/esql/stats/SearchStats.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23446.json"