CVE-2026-78587

Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 19:11


NVD link : CVE-2026-78587

Mitre link : CVE-2026-78587

CVE.ORG link : CVE-2026-78587


JSON object : View

Products Affected

elastic

  • fleet_server
CWE
CWE-863

Incorrect Authorization