SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-78609

MEDIUM · CVSS 5.4 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-05

CyberRota Analysis

AI-Generated

Elastic Cloud on Kubernetes (ECK) is vulnerable to incorrect authorization, allowing an attacker with limited permissions in one namespace to manipulate data through metadata spoofing. This could result in unauthorized modifications to the Elasticsearch client trust bundle in a different namespace, potentially compromising data integrity and security. Organizations using Kubernetes, particularly those deploying ECK, should prioritize addressing this vulnerability to safeguard their environments.

CVE
CVE-2026-78609
Severity
MEDIUM
CVSS
5.4
EPSS
0.09%
Kubernetes

Original NVD Description

Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.

Related CVEs

Other vulnerabilities affecting the same vendor(s)