CVE-2026-78607

Summary

Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.

Affected Software

VendorProductVersion RangeStatus
ElasticElasticsearch8.0.0 <= 8.19.18affected
ElasticElasticsearch9.0.0 <= 9.3.7affected
ElasticElasticsearch9.4.0 <= 9.4.3affected
ElasticElasticsearch9.5.0affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References