CVE-2026-78600

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elastic_cloud_on_kubernetes:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 19:15


NVD link : CVE-2026-78600

Mitre link : CVE-2026-78600

CVE.ORG link : CVE-2026-78600


JSON object : View

Products Affected

elastic

  • elastic_cloud_on_kubernetes
CWE
CWE-459

Incomplete Cleanup