CVE-2026-78600
CVE-2026-78600 is a low-severity vulnerability in Elastic Elastic Cloud On Kubernetes with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-459.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-459
- Affected product: Elastic Elastic Cloud On Kubernetes
- Published:
- Last modified:
Description
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
Frequently asked questions
- What is CVE-2026-78600?
- Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
- How severe is CVE-2026-78600?
- CVE-2026-78600 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-78600 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-78600?
- CVE-2026-78600 affects Elastic Elastic Cloud On Kubernetes. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-78600?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-78600 published?
- CVE-2026-78600 was published on 2026-09-02 and last updated on 2026-09-03.
References
Affected products (1)
- cpe:2.3:a:elastic:elastic_cloud_on_kubernetes:*:*:*:*:*:*:*:*
More vulnerabilities in Elastic Elastic Cloud On Kubernetes
- CVE-2020-7010 — High (CVSS 7.5): Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If…
- CVE-2026-72648 — Medium (CVSS 6.5): Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK)…
- CVE-2026-72640 — Medium (CVSS 6.5): The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it…
- CVE-2026-78609 — Medium (CVSS 5.4): Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data…
- CVE-2023-31416 — Medium (CVSS 5.3): Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous…
All CVEs affecting Elastic Elastic Cloud On Kubernetes →
Other CWE-459 vulnerabilities
- CVE-2023-36468 — Critical (CVSS 9.9): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki…
- CVE-2022-45347 — Critical (CVSS 9.8): Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session…
- CVE-2021-45330 — Critical (CVSS 9.8): An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies…
- CVE-2021-45706 — Critical (CVSS 9.8): An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust. Dropped memory is not zeroed out for an enum.
- CVE-2021-32928 — Critical (CVSS 9.8): The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License…
- CVE-2020-13451 — Critical (CVSS 9.8): An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to…