SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-78600

LOW · CVSS 3.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-05

CyberRota Analysis

AI-Generated

Elastic Cloud on Kubernetes (ECK) is vulnerable due to incomplete cleanup of authentication credentials, which can persist even after RBAC enforcement denies cross-namespace associations. This flaw allows low-privileged tenants to maintain unauthorized read access to associated Elasticsearch clusters, potentially leading to privilege abuse. Organizations using Kubernetes with ECK should prioritize remediation to mitigate the risk of unauthorized data access.

CVE
CVE-2026-78600
Severity
LOW
CVSS
3.5
EPSS
0.18%
Kubernetes

Original NVD Description

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

Related CVEs

Other vulnerabilities affecting the same vendor(s)