Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents. | |
| Title | Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Operations | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-02T15:58:11.187Z
Reserved: 2026-08-24T21:13:45.972Z
Link: CVE-2026-78587
Updated: 2026-09-02T15:50:01.580Z
Status : Awaiting Analysis
Published: 2026-09-02T15:17:40.190
Modified: 2026-09-02T19:23:13.660
Link: CVE-2026-78587
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization