Incorrect authorization in Elastic Cloud on Kubernetes - CVE-2026-78609
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to modify data in a separate namespace.
The vulnerability exists due to incorrect authorization in the Elastic Cloud on Kubernetes trust bundle management for Elasticsearch client certificates when processing Secrets in namespaces monitored by ECK. A remote user can create a Secret with attacker-controlled certificate material to modify data in a separate namespace.
The issue affects multi-tenant Kubernetes environments where separate tenants can create Secrets in namespaces monitored by ECK. The confidentiality and integrity impact is most significant when Elasticsearch client certificate authentication is configured and active.