Code Injection Vulnerability in Fleet Server by Elastic
CVE-2026-72676

6.5MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
13 August 2026

What is CVE-2026-72676?

A code injection vulnerability in Fleet Server allows attackers to execute unauthorized scripts by manipulating output configuration identifiers. When these identifiers are improperly validated, they may contain script syntax, which is then executed within a server-side script during the routine processing of agent policies. This unauthorized script execution poses a significant risk, as it enables attackers to run arbitrary code on the server, potentially compromising the integrity and confidentiality of the system.

Affected Version(s)

Fleet Server 8.5.0 <= 8.19.19

Fleet Server 9.0.0 <= 9.4.4

Fleet Server 9.5.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.