CVE-2026-78587: Elastic Fleet Server

Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.

Affected products

  • Elastic Fleet Server: from 8.0.0, before 8.19.16 (fixed in 8.19.16); from 9.0.0, before 9.3.5 (fixed in 9.3.5); from 9.4.0, before 9.4.2 (fixed in 9.4.2)

Published 2026-09-02. Last modified 2026-09-03.