Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-72657

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.19.20 (исключая)
cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.4.5 (исключая)
cpe:2.3:a:elastic:fleet_server:9.5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.0028
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
github
около 1 месяца назад

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to.

EPSS

Процентиль: 21%
0.0028
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639