← back
CVE-2026-78609mediumCWE-863

Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of Data

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
Elastic · Eck Operator