Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic fleet Server |
|
| Vendors & Products |
Elastic
Elastic fleet Server |
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents. | |
| Title | Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Operations | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-02T15:58:11.187Z
Reserved: 2026-08-24T21:13:45.972Z
Link: CVE-2026-78587
Updated: 2026-09-02T15:50:01.580Z
Status : Awaiting Analysis
Published: 2026-09-02T15:17:40.190
Modified: 2026-09-02T19:23:13.660
Link: CVE-2026-78587
No data.
OpenCVE Enrichment
Updated: 2026-09-03T10:45:04Z
-
CWE-863
Incorrect Authorization