Elastic Cloud on Kubernetes 3.5.0 Security Update (ESA-2026-146)

Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

Affected Versions:

  • All versions from 2.6.0 up to and including 3.4.1

Affected Configurations:
Deployments where cross-namespace resource associations have been established and are subsequently subject to RBAC enforcement -- either through enabling RBAC controls on the operator or through revocation of previously granted cross-namespace permissions. Deployments that have never used cross-namespace associations, or deployments in which RBAC enforcement has never been applied, are not affected.

Solutions and Mitigations:
The issue is resolved in Elastic Cloud on Kubernetes version 3.5.0.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.

Severity: CVSSv3.1: Low ( 3.5 ) - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
CVE ID: CVE-2026-78600
Problem Type: CWE-459 - Incomplete Cleanup
Impact: Impact: CAPEC-122 - Privilege Abuse