6.5

CVE-2026-72657

Authorization Bypass Through User-Controlled Key in Fleet Server Leading to Information Disclosure

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elastic ≫ Fleet Server Version >= 8.3.0 < 8.19.20
Elastic ≫ Fleet Server Version >= 9.0.0 < 9.4.5
Elastic ≫ Fleet Server Version 9.5.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.188
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@elastic.co 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://discuss.elastic.co/t/fleet-server-8-19-20-9-4-5-9-5-1-security-update-esa-2026-112/389509
Vendor Advisory