SB2026090229 - Multiple vulnerabilities in Elastic Cloud on Kubernetes



SB2026090229 - Multiple vulnerabilities in Elastic Cloud on Kubernetes

Published: September 2, 2026

Security Bulletin ID SB2026090229
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Incomplete cleanup (CVE-ID: CVE-2026-78600)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incomplete cleanup in cross-namespace association credential handling when RBAC enforcement denies a cross-namespace association. A remote user can retain previously issued credentials to disclose sensitive information.

Only deployments where cross-namespace resource associations were previously established and later became subject to RBAC enforcement are vulnerable.


2) Incorrect authorization (CVE-ID: CVE-2026-78609)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify data in a separate namespace.

The vulnerability exists due to incorrect authorization in the Elastic Cloud on Kubernetes trust bundle management for Elasticsearch client certificates when processing Secrets in namespaces monitored by ECK. A remote user can create a Secret with attacker-controlled certificate material to modify data in a separate namespace.

The issue affects multi-tenant Kubernetes environments where separate tenants can create Secrets in namespaces monitored by ECK. The confidentiality and integrity impact is most significant when Elasticsearch client certificate authentication is configured and active.


Remediation

Install update from vendor's website.