Impact
An incorrect authorization check in Elastic Fleet Server allows any authenticated agent to interfere with multipart data upload sessions belonging to other agents, preventing those uploads from completing. This flaw corresponds to CWE‑863 and results in a denial of service for agent upload operations without providing extra privileges or data exposure.
Affected Systems
Elastic Fleet Server (all deployed instances), with no specific version information available in the advisory.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. EPSS is not available and the vulnerability is not listed in CISA KEV. Exploitation requires only authentication; an attacker who can log in to any agent can send a multipart request to abort another agent’s active upload session. No elevated privileges or network reachability beyond authentication are needed, making the attack straightforward for authenticated adversaries but limiting overall impact to service disruption.
OpenCVE Enrichment