Authorization Bypass Vulnerability in Elastic Fleet Server by Elastic
CVE-2026-72657

6.5MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
13 August 2026

What is CVE-2026-72657?

An authorization bypass vulnerability in Elastic's Fleet Server allows authenticated users with valid agent credentials to access policies that they are not assigned to. This issue arises from the flawed reliance on user-controlled variables for artifact downloads, which are not properly validated against the server-side records of agent assignments. As a result, an attacker can manipulate requests to retrieve sensitive information leading to unauthorized data disclosure.

Affected Version(s)

Fleet Server 8.3.0 <= 8.19.19

Fleet Server 9.0.0 <= 9.4.4

Fleet Server 9.5.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.