CVE-2026-78609
Received Received - Intake

Incorrect Authorization in Elastic Cloud on Kubernetes

Vulnerability report for CVE-2026-78609, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Elastic

Description

Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
elastic cloud_on_kubernetes *
elastic cloud_on_kubernetes From 2.6.0 (inc) to 3.4.1 (inc)
elastic cloud_on_kubernetes 3.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78609 is an Incorrect Authorization vulnerability in Elastic Cloud on Kubernetes (ECK) versions 2.6.0 through 3.4.1. It allows an attacker with limited Kubernetes permissions in one namespace to inject malicious certificate material into the Elasticsearch client trust bundle in another namespace via Metadata Spoofing. This could lead to unauthorized modification of data.

Detection Guidance

To detect this vulnerability, check the version of Elastic Cloud on Kubernetes (ECK) running in your environment. Run the command kubectl get deployment -n elastic-system eck-operator-controller-manager to verify the ECK version. If the version is between 2.6.0 and 3.4.1, the system is vulnerable.

Impact Analysis

An attacker could exploit this to modify data in Elasticsearch, particularly in multi-tenant Kubernetes environments where tenants can create Secrets in monitored namespaces. This may result in data corruption or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized data modification, potentially violating compliance requirements for GDPR (data integrity) and HIPAA (confidentiality). Organizations may face legal or regulatory penalties if data is compromised.

Mitigation Strategies

Upgrade Elastic Cloud on Kubernetes (ECK) to version 3.5.0 or later immediately. This can be done by following the official Elastic documentation for upgrading ECK. Ensure no workarounds are applied as none are recommended for this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78609. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart