Impact
The vulnerability allows an attacker to obtain sensitive authentication credentials that ECK stores in cleartext within a workload specification. When a Fleet Server resource is reconciled, the service account token used to authenticate to Elasticsearch is embedded directly in the generated spec instead of being referenced from a Kubernetes Secret. An attacker who can read the spec in the affected namespace can therefore read a live Elasticsearch credential, even if RBAC does not allow access to secrets.
Affected Systems
Elastic Cloud on Kubernetes (ECK) Operator; the specific version affected is not disclosed in the CVE data, so all installations of the ECK Operator that employ Fleet Server resources are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the EPSS score is not available and the vulnerability is not listed in KEV, there is no definitive evidence of current exploitation. The likely attack vector is that a principal with permissions to view workload specifications in a namespace can read the cleartext token, leading to credential theft.
OpenCVE Enrichment