VendorsElasticelastic_cloud_on_kubernetesany version
Vulnerabilities

Elastic Cloud on Kubernetes (ECK) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-7010
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.
Published 2020-06-03 · Modified
7.5EPSS 0.014
CVE-2026-72648
Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72640
Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret Disclosure
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-78609
Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of Data
Published 2026-09-02 · Analyzed
5.4EPSS 0.002
CVE-2023-31416
Elastic Cloud on Kubernetes (ECK) secret token configuration issue
Published 2023-10-26 · Modified
5.3EPSS 0.004
CVE-2026-78600
Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention
Published 2026-09-02 · Analyzed
3.5EPSS 0.003