Junglewise Threat Intelligence

CVE-2026-78607: Elastic Elasticsearch missing authorization in custom inference service

CVE-2026-78607 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a widely-used search and analytics platform, contains a missing authorization flaw in its custom inference service that can be exploited by users with basic inference execution privileges. An attacker with these limited permissions could redirect inference traffic to attacker-controlled servers and extract administrator-provisioned credentials, leading to credential exposure and potential further compromise of the system.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the Elasticsearch custom inference service component. Users holding only inference execution privileges can manipulate the inference service to redirect outbound traffic to destinations of their choosing and expose credentials provisioned by administrators. The flaw requires the deployment to use the custom inference service type with secret-backed configuration and requires the attacker to have inference execution privileges. The attack is network-reachable and requires only valid low-privilege user credentials. Patches are available in Elasticsearch versions 8.19.19, 9.3.8, 9.4.4, and 9.5.1; users unable to upgrade have no available workarounds.

Affected products

  • Elastic Elasticsearch 8.0.0–8.19.18, 9.0.0–9.3.7, 9.4.0–9.4.3, 9.5.0

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Patches released in versions 8.19.19, 9.3.8, 9.4.4, 9.5.1

References

Related threats