Executive brief
Fleet Server is a component that manages agent communications and data collection for the Elastic Stack. The vulnerability allows any authenticated agent to disrupt upload operations of other agents, preventing them from successfully uploading files. This results in denial of service for critical agent reporting and data collection activities.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in Fleet Server's multi-part data upload handling. The server fails to verify that an upload session belongs to the authenticated agent attempting to access it, allowing any enrolled agent to interfere with another agent's active upload sessions. The attack requires an attacker to be an authenticated agent with valid enrollment credentials but does not require administrator privileges. An attacker can disrupt agent uploads, preventing legitimate agents from submitting data. The issue is patched in Fleet Server versions 8.19.16, 9.3.5, and 9.4.2.
Affected products
- Elastic Fleet Server 8.0.0 through 8.19.15, 9.0.0 through 9.3.4, 9.4.0 through 9.4.1
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Patched in Fleet Server 8.19.16, 9.3.5, and 9.4.2