Incomplete cleanup in Elastic Cloud on Kubernetes - CVE-2026-78600
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incomplete cleanup in cross-namespace association credential handling when RBAC enforcement denies a cross-namespace association. A remote user can retain previously issued credentials to disclose sensitive information.
Only deployments where cross-namespace resource associations were previously established and later became subject to RBAC enforcement are vulnerable.