Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-3-5-0-security-update-esa-2026-146/390106 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-02 15:17
Updated : 2026-09-03 19:15
NVD link : CVE-2026-78600
Mitre link : CVE-2026-78600
CVE.ORG link : CVE-2026-78600
JSON object : View
Products Affected
elastic
- elastic_cloud_on_kubernetes
CWE
CWE-459
Incomplete Cleanup
