Authorization Flaw in Fleet Server by Elastic
CVE-2026-78587

3.1LOW

Key Information:

Vendor

Elastic

Vendor
CVE Published:
2 September 2026

What is CVE-2026-78587?

An authorization flaw in Fleet Server allows authenticated agents to disrupt data upload sessions belonging to other agents. During multi-part upload operations, the system fails to validate session ownership properly. This oversight may result in denial of service for affected agents, enabling unauthorized interference with ongoing uploads. It is crucial for users to apply security updates to mitigate potential exploitation risks.

Affected Version(s)

Fleet Server 8.0.0 <= 8.19.15

Fleet Server 9.0.0 <= 9.3.4

Fleet Server 9.4.0 <= 9.4.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.