Executive brief
Fleet Server is Elastic's agent management and policy distribution system used to deploy security and monitoring agents across enterprise infrastructure. An authorization flaw allows authenticated users with valid agent credentials to retrieve policies they are not assigned to, potentially exposing sensitive configuration and policy details intended only for other agents or deployments.
Technical details
A CWE-639 authorization bypass vulnerability exists in Fleet Server's artifact download mechanism. The authorization decision relies on a client-supplied value that is persisted without validation against the server-side record of the requesting agent's actual policy assignments. An authenticated attacker with a valid enrolled agent credential can manipulate this client-supplied value to retrieve policies belonging to other agents or deployments. The vulnerability affects all configurations and versions 8.3.0–8.19.19, 9.0.0–9.4.4, and 9.5.0. No authentication bypass is required; the attacker must already possess valid enrolled agent credentials. The fix is available in versions 8.19.20, 9.4.5, and 9.5.1.
Affected products
- Elastic Fleet Server 8.3.0 to 8.19.19, 9.0.0 to 9.4.4, 9.5.0
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: Fixed in versions 8.19.20, 9.4.5, and 9.5.1