CVE-2026-78607: Elastic Elasticsearch
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
Affected products
- Elastic Elasticsearch: from 8.0.0, before 8.19.19 (fixed in 8.19.19); from 9.0.0, before 9.3.8 (fixed in 9.3.8); from 9.4.0, before 9.4.4 (fixed in 9.4.4); version 9.5.0 only
Published 2026-09-01. Last modified 2026-09-02.