PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72648 Elastic CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-72648 is a Cleartext Storage of Sensitive Information vulnerability in Elastic Cloud on Kubernetes (ECK). During reconciliation of a Fleet Server resource that authenticates to Elasticsearch with a service account token, ECK writes the token in cleartext to the generated workload specification instead of referencing it from the Kubernetes Secret. This allows any principal able to read workload specifications in the affected namespace to access a live Elasticsearch credential, even without Kubernetes RBAC access to Secrets. The vulnerability has a CVSS score of 6.5 (MEDIUM severity). The CVE record was published on 2026-08-13T20:17:25.160Z and has not been modified since then. The NVD entry is currently Analyzed. Elastic Cloud on Kubernetes (ECK) users, administrators of Kubernetes environments with ECK deployed, security teams responsible for monitoring and protecting sensitive data in cloud-native environments, and Elastic customers using Fleet Server resources for Elasticsearch authentication should assess and mitigate this vulnerability. Confirm whether affected Elastic Cloud on Kubernetes (ECK) deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review compensating controls for exposed systems while remediation is scheduled and verified. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Vendor
Elastic
Product
Eck Operator
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-04
Advisory published
2026-08-13
Advisory updated
2026-09-04

Who should care

Elastic Cloud on Kubernetes (ECK) users, administrators of Kubernetes environments with ECK deployed, security teams responsible for monitoring and protecting sensitive data in cloud-native environments, and Elastic customers using Fleet Server resources for Elasticsearch authentication.

Technical summary

CVE-2026-72648 is a Cleartext Storage of Sensitive Information vulnerability in Elastic Cloud on Kubernetes (ECK). During reconciliation of a Fleet Server resource that authenticates to Elasticsearch with a service account token, ECK writes the token in cleartext to the generated workload specification instead of referencing it from the Kubernetes Secret. This allows any principal able to read workload specifications in the affected namespace to access a live Elasticsearch credential, even without Kubernetes RBAC access to Secrets. The vulnerability has a CVSS score of 6.5 (MEDIUM severity).

Defensive priority

CVE-2026-72648 is rated CVSS 6.5 MEDIUM; Elastic Cloud on Kubernetes (ECK) stores sensitive information in cleartext environment variables, allowing information disclosure via Retrieve Embedded Sensitive Data. Principals able to read workload specifications in the affected namespace can access live Elasticsearch credentials even without Kubernetes RBAC access to Secrets.

Recommended defensive actions

  • Inventory and assess ECK deployments for exposure to CVE-2026-72648, focusing on namespaces with Fleet Server resources.
  • Restrict access to workload specifications in affected namespaces using Kubernetes RBAC.
  • Implement compensating controls such as monitoring for suspicious access to workload specifications.
  • Apply the vendor's security update (ESA-2026-113) for Elastic Cloud on Kubernetes version 3.5.0 or later.
  • Review and update Elasticsearch service account token management practices to avoid similar issues in the future.

Evidence notes

The CVE-2026-72648 issue arises from Elastic Cloud on Kubernetes (ECK) storing a service account token for Elasticsearch authentication in cleartext within workload specifications during Fleet Server resource reconciliation. This allows any principal with read access to workload specifications in the affected namespace to obtain a live Elasticsearch credential, even without Kubernetes RBAC permissions to access Secrets. The issue was publicly disclosed on 2026-08-13 and last modified on 2026-09-04 according to the CVE and NVD records.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72648 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72648

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72648 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72648

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-3-5-0-security-update-esa-2026-113/389493

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.