
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78607 is a Missing Authorization (CWE-862) vulnerability in the Elasticsearch custom inference service that enables information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding only inference execution privileges can redirect outbound inference traffic to an attacker-controlled destination and expose administrator-provisioned credentials. The vulnerability affects Elasticsearch versions 8.0.0–8.19.18, 9.0.0–9.3.7, 9.4.0–9.4.3, and 9.5.0. It was published on September 1, 2026, with patches released the same day. The CVSS v3.1 base score is 7.1 (High) (GitHub Advisory, Elastic Advisory).
The root cause is CWE-862 (Missing Authorization) in Elasticsearch's custom inference service, where insufficient authorization checks allow a low-privileged user to manipulate inference endpoint configurations. An authenticated attacker with only inference execution privileges can abuse this gap to redirect outbound inference traffic to an arbitrary, attacker-controlled destination — a form of server-side request redirection. This redirection causes the Elasticsearch service to transmit administrator-provisioned credentials (e.g., API keys or secrets configured for the inference endpoint) to the attacker's server. No user interaction is required, and the attack is conducted entirely over the network (GitHub Advisory, Elastic Advisory).
Successful exploitation results in high confidentiality impact through the exposure of administrator-provisioned credentials (such as API keys or service account secrets) and low integrity impact due to the ability to redirect inference traffic. An attacker who obtains these credentials could use them for lateral movement, unauthorized access to downstream AI/ML services, or further privilege escalation within the environment. Availability is not directly impacted, but the compromise of administrative credentials could have cascading effects across integrated services (GitHub Advisory, Elastic Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.165%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with at minimum inference execution privileges, limiting the attack surface to internal or compromised users (Elastic Advisory).
monitor_inference or equivalent role).Authorization headers or API key material sent to non-approved endpoints.PUT /_inference/ or POST /_inference/) by low-privileged users modifying endpoint configurations; repeated inference execution requests to newly created or modified custom endpoints.Elastic has released patched versions addressing this vulnerability: 8.19.19, 9.3.8, 9.4.4, and 9.5.1. Organizations should upgrade to one of these versions immediately. As an interim measure, restrict inference execution privileges to only trusted users who genuinely require this functionality, and audit existing inference service configurations and credential usage patterns for signs of unauthorized access or traffic redirection (Elastic Advisory, GitHub Advisory).
The vulnerability was covered in the context of Microsoft's September 2026 Patch Tuesday roundup by BleepingComputer, though it is an Elastic-originated issue (BleepingComputer). Threat intelligence aggregators such as VulDB and radar.offseq.com catalogued the vulnerability shortly after disclosure. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."