Incorrect Authorization Vulnerability in Elastic Cloud on Kubernetes by Elastic
CVE-2026-78609

5.4MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
2 September 2026

What is CVE-2026-78609?

An incorrect authorization vulnerability exists in Elastic Cloud on Kubernetes (ECK) that can allow an attacker with limited Kubernetes permissions confined to a single namespace to manipulate data. By leveraging metadata spoofing techniques, an unauthorized actor could introduce malicious certificate material into the Elasticsearch client trust bundle that ECK manages in a different namespace. This can lead to unauthorized data modifications and compromise the integrity of the Elasticsearch deployment, necessitating immediate attention to ensure security and proper namespace permissions.

Affected Version(s)

Eck Operator 2.6.0 <= 3.4.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.