CVE-2026-78609

Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elastic_cloud_on_kubernetes:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-04 16:39


NVD link : CVE-2026-78609

Mitre link : CVE-2026-78609

CVE.ORG link : CVE-2026-78609


JSON object : View

Products Affected

elastic

  • elastic_cloud_on_kubernetes
CWE
CWE-863

Incorrect Authorization