Authorization Bypass Vulnerability in Elastic Fleet Server by Elastic
CVE-2026-72657
6.5MEDIUM
What is CVE-2026-72657?
An authorization bypass vulnerability in Elastic's Fleet Server allows authenticated users with valid agent credentials to access policies that they are not assigned to. This issue arises from the flawed reliance on user-controlled variables for artifact downloads, which are not properly validated against the server-side records of agent assignments. As a result, an attacker can manipulate requests to retrieve sensitive information leading to unauthorized data disclosure.
Affected Version(s)
Fleet Server 8.3.0 <= 8.19.19
Fleet Server 9.0.0 <= 9.4.4
Fleet Server 9.5.0