Elastic Cloud on Kubernetes (ECK) 中的授权不正确(CWE-863)可能导致通过元数据篡改(CAPEC-690)发生未授权的数据修改。一个仅在单一命名空间内拥有有限 Kubernetes 权限的主体,能够使攻击者控制的证书材料被纳入 ECK 在另一个命名空间中管理的 Elasticsearch 客户端信任证书包中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Eck Operator | 2.6.0 ~ 3.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78604 | 7.8 HIGH | Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Pr |
| CVE-2026-78590 | 7.3 HIGH | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori |
| CVE-2026-78588 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Serv |
| CVE-2026-78586 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-78599 | 6.5 MEDIUM | Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources |
| CVE-2026-78591 | 6.3 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L |
| CVE-2026-78601 | 5.5 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure |
| CVE-2026-78598 | 5.4 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine |
| CVE-2026-78602 | 5.3 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading |
| CVE-2026-78594 | 4.9 MEDIUM | Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of |
| CVE-2026-82293 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption |
| CVE-2026-78584 | 4.3 MEDIUM | Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure |
| CVE-2026-78600 | 3.5 LOW | Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace |
| CVE-2026-78587 | 3.1 LOW | Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Opera |
No comments yet