« Volver al listado

CVE-2026-72657

Estado: AnalizadaMedia (6.5)—

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72657",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-72657",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-13T19:51:05.667444Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@elastic.co",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@elastic.co",
      "affectedData": [
        {
          "vendor": "Elastic",
          "product": "Fleet Server",
          "versions": [
            {
              "status": "affected",
              "version": "8.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.19.19"
            },
            {
              "status": "affected",
              "version": "9.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.4.4"
            },
            {
              "status": "affected",
              "version": "9.5.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-13T20:17:25.870",
  "references": [
    {
      "url": "https://discuss.elastic.co/t/fleet-server-8-19-20-9-4-5-9-5-1-security-update-esa-2026-112/389509",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@elastic.co"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@elastic.co",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to."
    }
  ],
  "lastModified": "2026-09-04T20:17:55.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32BDB1E6-378D-4F9E-AA4F-01AF485D4E8E",
              "versionEndExcluding": "8.19.20",
              "versionStartIncluding": "8.3.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F3D7A90-62AA-4F93-B8E9-7F5CBE294B84",
              "versionEndExcluding": "9.4.5",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:fleet_server:9.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3B2002A-7C58-4BA8-AC16-3B02CF8F40F3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@elastic.co"
}