VDB

CVE-2026-78600

CVE-2026-78600 PUBLISHED CVSS 3.5 LOW

Reported by elastic · Published September 2, 2026

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

Risk Scores

CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersions
ElasticEck Operator2.6.0
ElasticEck Operator2.6.0

Timeline

  • Sep 1, 2026 CVE Published
  • Sep 3, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 15, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›