PT-2026-71763 · Elastic · Cloud On Kubernetes

CVE-2026-72648

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elastic Cloud on Kubernetes (affected versions not specified)
Description Sensitive information is stored in cleartext within an environment variable. When reconciling a Fleet Server resource that authenticates to Elasticsearch using a service account token, the token is written directly into the generated workload specification. This occurs instead of referencing the Kubernetes Secret used for other credentials on the same path. Consequently, any principal with permissions to read workload specifications in the affected namespace can access a live Elasticsearch credential, bypassing Kubernetes RBAC restrictions that would otherwise prevent access to Secrets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72648

Affected Products

Cloud On Kubernetes