Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic fleet Server |
|
| Vendors & Products |
Elastic
Elastic fleet Server |
|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restricting it to safe characters. That identifier is later placed into a server-side script that Fleet Server builds as part of routine agent policy processing, so script syntax embedded in the identifier became part of the script that was executed rather than being treated as data. | |
| Title | Improper Control of Generation of Code in Fleet Server Leading to Code Injection | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:32:02.584Z
Reserved: 2026-08-10T11:17:49.704Z
Link: CVE-2026-72676
Updated: 2026-08-13T20:31:59.047Z
Status : Received
Published: 2026-08-13T20:17:28.257
Modified: 2026-08-13T21:18:12.223
Link: CVE-2026-72676
No data.
OpenCVE Enrichment
Updated: 2026-08-13T21:15:03Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')