Impact
The vulnerability in Fleet Server allows an authenticated individual who possesses a valid agent enrollment credential to supply a manipulated client‑supplied key that the server stores without verifying against the agent’s server‑side assignment. This mis‑validation permits the attacker to obtain the policy for an agent to which they are not authorized, exposing internal policy data that could reveal deployment configurations and other sensitive operational information.
Affected Systems
All Elastic Fleet Server deployments that have not applied the security update correcting the key validation flaw are affected. The CVE payload does not list specific product versions, so the risk applies to any release before the published fix is installed.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation has not been reported. However, the exploit requires an authenticated agent credential, which is typically held by privileged users or services, making the threat realistic. The likely attack vector is an authenticated operator manipulating the client value to request policy data from an unauthorized agent.
OpenCVE Enrichment