Improper Authorization in Elastic Cloud on Kubernetes by Elastic
CVE-2026-72640
6.5MEDIUM
What is CVE-2026-72640?
The Elastic Cloud on Kubernetes (ECK) operator is affected by a vulnerability that allows unauthorized access to secrets. The operator reads secret references from an annotation and fails to properly validate the namespace of these references. Consequently, a user with limited permissions in their own namespace can exploit this flaw by manipulating annotations. This enables them to trigger a resource reconciliation, using the operator’s cluster-wide secret permissions to copy sensitive data from other namespaces into accessible secrets.
Affected Version(s)
Eck Operator 3.0.0 <= 3.4.1