Cleartext Storage Vulnerability in Elastic Cloud on Kubernetes
CVE-2026-72648

6.5MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
13 August 2026

What is CVE-2026-72648?

The Elastic Cloud on Kubernetes (ECK) vulnerability arises from the cleartext storage of sensitive information, specifically a service account token, in workload specifications. When ECK processes a Fleet Server resource and stores the token directly in cleartext instead of referencing it from a secure Kubernetes Secret, it exposes the risk of unauthorized access. Any user with the ability to read the workload specifications in the affected namespace can potentially access live Elasticsearch credentials, regardless of whether they have permission to access the Secrets via Kubernetes RBAC. This can lead to information disclosure and significant security concerns within cloud-native environments.

Affected Version(s)

Eck Operator 3.0.0 <= 3.4.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.