Junglewise Threat Intelligence

CVE-2026-78587: Elastic Fleet Server incorrect authorization in multi-part upload

CVE-2026-78587 · Severity: low · CVSS 3.1 · Published 2026-09-02

Technologies: Elastic Fleet Server. Vendors: Elastic.

Executive brief

Fleet Server is a component that manages agent communications and data collection for the Elastic Stack. The vulnerability allows any authenticated agent to disrupt upload operations of other agents, preventing them from successfully uploading files. This results in denial of service for critical agent reporting and data collection activities.

Technical details

The vulnerability is an incorrect authorization flaw (CWE-863) in Fleet Server's multi-part data upload handling. The server fails to verify that an upload session belongs to the authenticated agent attempting to access it, allowing any enrolled agent to interfere with another agent's active upload sessions. The attack requires an attacker to be an authenticated agent with valid enrollment credentials but does not require administrator privileges. An attacker can disrupt agent uploads, preventing legitimate agents from submitting data. The issue is patched in Fleet Server versions 8.19.16, 9.3.5, and 9.4.2.

Affected products

  • Elastic Fleet Server 8.0.0 through 8.19.15, 9.0.0 through 9.3.4, 9.4.0 through 9.4.1

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Patched in Fleet Server 8.19.16, 9.3.5, and 9.4.2

References

Related threats