Description
Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.
Published: 2026-09-02
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization check in Elastic Fleet Server allows any authenticated agent to interfere with multipart data upload sessions belonging to other agents, preventing those uploads from completing. This flaw corresponds to CWE‑863 and results in a denial of service for agent upload operations without providing extra privileges or data exposure.

Affected Systems

Elastic Fleet Server (all deployed instances), with no specific version information available in the advisory.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity. EPSS is not available and the vulnerability is not listed in CISA KEV. Exploitation requires only authentication; an attacker who can log in to any agent can send a multipart request to abort another agent’s active upload session. No elevated privileges or network reachability beyond authentication are needed, making the attack straightforward for authenticated adversaries but limiting overall impact to service disruption.

Generated by OpenCVE AI on September 3, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Isolate the affected Fleet Server and halt all agent upload operations to prevent ongoing disruptions.
  • Monitor the system for repeated upload failures and document affected agents.
  • Check Elastic’s security advisories regularly and plan to upgrade Fleet Server to the latest release once a fix is available.
  • If a temporary fix is not yet released, restrict the upload endpoint to trusted sources or disable uploads until a patched version is deployed.

Generated by OpenCVE AI on September 3, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic fleet Server
Vendors & Products Elastic
Elastic fleet Server

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.
Title Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Operations
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Elastic Fleet Server
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:11.187Z

Reserved: 2026-08-24T21:13:45.972Z

Link: CVE-2026-78587

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:01.580Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:40.190

Modified: 2026-09-03T19:11:53.153

Link: CVE-2026-78587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:04Z

Weaknesses