Vulnerability Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Fleet Server | >= 8.3.0, < 8.19.20 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-72657?
CVE-2026-72657 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for arti...
How severe is CVE-2026-72657?
CVE-2026-72657 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72657?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Fleet Server.