CVE-2026-78587
- EPSS 0.2%
- Veröffentlicht 02.09.2026 14:43:26
- Zuletzt bearbeitet 03.09.2026 19:11:53
Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing ...
CVE-2026-72657
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:13:28
- Zuletzt bearbeitet 04.09.2026 20:17:55
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value t...
CVE-2026-72676
- EPSS 0.36%
- Veröffentlicht 13.08.2026 19:11:26
- Zuletzt bearbeitet 04.09.2026 20:21:02
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restric...
CVE-2026-56150
- EPSS 0.35%
- Veröffentlicht 01.07.2026 16:26:31
- Zuletzt bearbeitet 06.07.2026 18:51:50
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory...
- EPSS 0.27%
- Veröffentlicht 23.01.2025 08:15:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.
CVE-2023-46667
- EPSS 0.55%
- Veröffentlicht 26.10.2023 01:15:07
- Zuletzt bearbeitet 21.11.2024 08:29:01
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and po...