SB2026090229 - Multiple vulnerabilities in Elastic Cloud on Kubernetes
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Incomplete cleanup (CVE-ID: CVE-2026-78600)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incomplete cleanup in cross-namespace association credential handling when RBAC enforcement denies a cross-namespace association. A remote user can retain previously issued credentials to disclose sensitive information.
Only deployments where cross-namespace resource associations were previously established and later became subject to RBAC enforcement are vulnerable.
2) Incorrect authorization (CVE-ID: CVE-2026-78609)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify data in a separate namespace.
The vulnerability exists due to incorrect authorization in the Elastic Cloud on Kubernetes trust bundle management for Elasticsearch client certificates when processing Secrets in namespaces monitored by ECK. A remote user can create a Secret with attacker-controlled certificate material to modify data in a separate namespace.
The issue affects multi-tenant Kubernetes environments where separate tenants can create Secrets in namespaces monitored by ECK. The confidentiality and integrity impact is most significant when Elasticsearch client certificate authentication is configured and active.
Remediation
Install update from vendor's website.