Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace. | |
| Title | Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of Data | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-02T15:58:13.193Z
Reserved: 2026-08-24T21:13:52.890Z
Link: CVE-2026-78609
Updated: 2026-09-02T15:51:38.241Z
Status : Awaiting Analysis
Published: 2026-09-02T15:17:41.827
Modified: 2026-09-02T19:23:13.660
Link: CVE-2026-78609
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization