CVE-2026-78600: Elastic Cloud On Kubernetes

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

Affected products

  • Elastic Elastic Cloud On Kubernetes: from 2.6.0, before 3.5.0 (fixed in 3.5.0)

Published 2026-09-02. Last modified 2026-09-03.