CVE-2026-72648
Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearch with a service account token, the token is written into the generated workload specification in cleartext rather than being referenced from the Kubernetes Secret that ECK maintains for the other credentials on the same path. Any principal able to read workload specifications in the affected namespace can therefore read a live Elasticsearch credential, even when Kubernetes RBAC does not grant that principal access to Secrets.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-526
- Published
- 2026-08-13
- Last modified
- 2026-08-13
Affected products
- Elastic Eck Operator
Weakness type
Related vulnerabilities
- CVE-2026-76227 — Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
- CVE-2026-49377 — In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- CVE-2026-45370 — python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
- CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
- CVE-2025-36105 — IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability
- CVE-2025-27899 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-36017 — IBM Controller Information Disclosure
- CVE-2025-9162 — Org.keycloak/keycloak-model-storage-service: variable injection into environment variables