Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98445.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-98445
Upstream
  • CVE-2026-78607
Published
2026-09-01T20:17:24Z
Modified
2026-09-02T14:16:06.609376229Z
Summary
CVE-2026-78607 affecting package rubygem-elasticsearch 8.9.0-1
Details

Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.

References

Affected packages

Azure Linux:3 / rubygem-elasticsearch

Package

Name
rubygem-elasticsearch
Purl
pkg:rpm/azure-linux/rubygem-elasticsearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
8.9.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98445.json"