CVE-2026-78587: Elastic Fleet Server
Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.
Affected products
- Elastic Fleet Server: from 8.0.0, before 8.19.16 (fixed in 8.19.16); from 9.0.0, before 9.3.5 (fixed in 9.3.5); from 9.4.0, before 9.4.2 (fixed in 9.4.2)
Published 2026-09-02. Last modified 2026-09-03.