A vulnerability described as problematic has been identified in Elastic Eck Operator up to 3.4.1 . Affected by this issue is some unknown functionality of the component Fleet Server . Such manipulation leads to exposure of sensitive information through environmental variables. This vulnerability is documented as CVE-2026-72648 . The attack can be executed remotely. There is not any exploit available.