CVE-2026-78607 Missing Authorization (CWE-862) in the Elasticsearch… — CVE Notify — TG.ME

🚨 CVE-2026-78607
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.

🎖@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.19, 9.3.8, 9.4.4, 9.5.1 Security Update (ESA-2026-143)
Missing Authorization in Elasticsearch Leading to Information Disclosure Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution…
September 1, 2026 7