{"id":"AZL-98445","summary":"CVE-2026-78607 affecting package rubygem-elasticsearch 8.9.0-1","details":"Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.","modified":"2026-09-02T14:16:06.609376229Z","published":"2026-09-01T20:17:24Z","upstream":["CVE-2026-78607"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78607"}],"affected":[{"package":{"name":"rubygem-elasticsearch","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rubygem-elasticsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"8.9.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98445.json"}}],"schema_version":"1.9.0"}