Impact
The reported issue is an incomplete cleanup that leaves authentication credentials in place after a cross‑namespace association request is denied by RBAC. The lingering credentials give a tenant with low privileges read access to an Elasticsearch cluster they should not see. The weakness is a classic instance of over‑persistent information leading to privilege abuse.
Affected Systems
The vulnerability applies to Elastic Cloud on Kubernetes, specifically the ECK Operator. No precise version is identified in the entry, but all releases affected by the incomplete cleanup must be addressed.
Risk and Exploitability
The CVSS score of 3.5 indicates a low overall severity, and no EPSS data or KEV listing is available, suggesting that the vulnerability is not currently widely exploited. The likely attack vector is a local or cross‑namespace interaction where RBAC is enforced; it is inferred from the description that the attacker could trigger the flaw by attempting a denied association. Organizations using ECK should treat the issue as a low‑assurance risk but still remediate promptly to prevent unauthorized credential retention.
OpenCVE Enrichment