CVE-2026-78609
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 02, 2026
Vendor
unknown
Description
Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.