CVE-2026-78607
largeMissing Authorization in Elasticsearch Custom Inference Service Exposes Credentials
CVE-2026-78607 is a missing-authorization flaw (CWE-862) in the custom inference service of Elasticsearch. An authenticated user who holds only inference execution privileges can direct outbound inference traffic to a destination of their choosing, allowing them to observe that traffic and expose administrator-provisioned credentials (CVSS 3.1: 7.1, high confidentiality impact with low integrity impact). The flaw is triggered remotely with low privileges and no user interaction: any user authorized to run inference, but not administer the cluster, can abuse the missing authorization check. Elasticsearch deployments that provision custom inference services with credentials and grant inference execute privileges to non-administrator users are affected; the specific affected version ranges are those listed in Elastic's security advisory. No exploitation is currently known: EPSS is 0.2% (9th percentile), the issue is not in CISA KEV, and no public proof-of-concept exists.
What to do: Upgrade Elasticsearch to the patched release referenced in Elastic's security advisory for CVE-2026-78607. In the meantime, audit roles for users holding inference execute privileges, restrict or rotate administrator-provisioned credentials (e.g., API keys) configured on custom inference endpoints, and monitor outbound inference traffic for unexpected destinations.
| Elasticsearch | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
- Vendors
- elastic
- Products
- elasticsearch
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.