Missing Authorization in Elasticsearch - CVE-2026-78607
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the Elasticsearch custom inference service when handling inference execution requests. A remote user can direct outbound inference traffic to a destination of their choosing to disclose sensitive information.
Only deployments using the custom inference service type with secret-backed configuration are vulnerable.