ECK Incomplete Cleanup Enables LowPrivileged Privilege Abuse
CVE-2026-78600 Published on September 2, 2026
Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
Vulnerability Analysis
CVE-2026-78600 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Insufficient Cleanup Vulnerability?
The software does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVE-2026-78600 has been classified to as an Insufficient Cleanup vulnerability or weakness.
Affected Versions
Elastic Eck Operator:- Version 2.6.0, <= 3.4.1 is affected.