Incomplete Cleanup in Elastic Cloud on Kubernetes by Elastic
CVE-2026-78600

3.5LOW

Key Information:

Vendor

Elastic

Vendor
CVE Published:
2 September 2026

What is CVE-2026-78600?

An issue in Elastic Cloud on Kubernetes allows for potential unauthorized access due to improper cleanup procedures. Specifically, authentication credentials can persist even when access has been denied by Role-Based Access Control (RBAC) policies. This vulnerability enables a low-privileged tenant to retain unauthorized readable access to the associated Elasticsearch cluster, posing a significant security risk.

Affected Version(s)

Eck Operator 2.6.0 <= 3.4.1

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.