CVE-2026-78600CWE-459

CVE-2026-78600

Low · published September 2, 2026

CVSS v3.1
3.5
EPSS
0%
Percentile
7.4
In the wild
Unconfirmed
What it is

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

The record
Technical detail
CVSS v3.1
3.5 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00178 · 7.4th percentile
Weakness
CWE-459 · Incomplete Cleanup
Published
2026-09-02T19:17Z
Affected products (1)
ProductVersionsFixed in
elastic/elastic_cloud_on_kubernetes≥ 2.6.0, < 3.5.03.5.0
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 14:43Z
    Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention
    cvelistv5