Incorrect Auth in ECK Enables Namespace-Scoped Metadata Spoofing
CVE-2026-78609 Published on September 2, 2026
Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of Data
Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
Vulnerability Analysis
CVE-2026-78609 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-78609 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
Elastic Eck Operator:- Version 2.6.0, <= 3.4.1 is affected.