Description
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure through Missing Authorization
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw (CWE-862) in the custom inference service of Elastic Elasticsearch that can allow a user with only inference execution privileges to cause outbound inference traffic to be redirected to an arbitrary destination. By doing so, the attacker can obtain administrator‑provisioned credentials that are normally protected. The impact is the disclosure of privileged credentials and the potential to abuse inference traffic for malicious purposes. While the flaw only permits information disclosure, the exposed credentials create a broader attack surface for subsequent escalation.

Affected Systems

The affected product is Elastic:Elasticsearch. Specific affected versions were not listed in the CVE data, so the exact vulnerable releases are not identified. Organizations running any public-facing Elasticsearch node that uses the custom inference service should verify against the latest Elasticsearch security updates provided by Elastic.

Risk and Exploitability

The CVSS score of 5.4 places the vulnerability in the medium risk range. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, indicating no known active exploitation. The likely attack requires the attacker to possess inference execution privileges, which may be limited to certain users, but compromised or weakly protected accounts could satisfy this requirement. In practice, the acceptability of exploitation depends on the presence of such accounts and on network controls that limit outbound destinations. Overall, the risk is moderate; however, the exposure of credentials elevates the potential for downstream attacks.

Generated by OpenCVE AI on September 2, 2026 at 02:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Elasticsearch to a version that contains the official patch referenced in the Elastic security update; review the Elastic discussion thread for the specific release details.
  • If an upgrade cannot be applied immediately, restrict the inference execution role to administrators only and eliminate the role for ordinary users; ensure that the role grants no access to external network destinations.
  • Disable the custom inference service if it is not required, or confine outbound inference traffic to a locked-down network segment controlled by a firewall or security group.
  • Enable detailed auditing on inference execution and monitor logs for unusual outbound traffic patterns or credential leaks; generate alerts for credentials that appear in query payloads or responses.
  • Perform a credential rotation for all administrator accounts that are exposed as part of inference responses, and enforce strong password or token policies for these accounts.

Generated by OpenCVE AI on September 2, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:9.5.0:*:*:*:*:*:*:*

Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elasticsearch
Vendors & Products Elastic
Elastic elasticsearch

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
Title Missing Authorization in Elasticsearch Leading to Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Elastic Elasticsearch
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:41:19.721Z

Reserved: 2026-08-24T21:13:52.890Z

Link: CVE-2026-78607

cve-icon Vulnrichment

Updated: 2026-09-01T19:41:16.577Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:24.030

Modified: 2026-09-02T18:50:29.990

Link: CVE-2026-78607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:15:12Z

Weaknesses