Incorrect authorization in Elastic Cloud on Kubernetes - CVE-2026-78609

 

Incorrect authorization in Elastic Cloud on Kubernetes - CVE-2026-78609

Published: September 2, 2026


Vulnerability identifier: #VU146673
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78609
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify data in a separate namespace.

The vulnerability exists due to incorrect authorization in the Elastic Cloud on Kubernetes trust bundle management for Elasticsearch client certificates when processing Secrets in namespaces monitored by ECK. A remote user can create a Secret with attacker-controlled certificate material to modify data in a separate namespace.

The issue affects multi-tenant Kubernetes environments where separate tenants can create Secrets in namespaces monitored by ECK. The confidentiality and integrity impact is most significant when Elasticsearch client certificate authentication is configured and active.


Affected software

Elastic Cloud on Kubernetes

How to mitigate CVE-2026-78609

Install security update from vendor's website.

Elastic Cloud on Kubernetes - update to 3.5.0

External References

Related Security Bulletins