Incorrect authorization in Fleet Server - CVE-2026-78587
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service of agent upload operations.
The vulnerability exists due to incorrect authorization in Fleet Server multi-part data upload operations when verifying session ownership during uploads. A remote user can interfere with active upload sessions belonging to other enrolled agents to cause a denial of service of agent upload operations.
All configurations are affected.