Incorrect authorization in Fleet Server - CVE-2026-78587

 

Incorrect authorization in Fleet Server - CVE-2026-78587

Published: September 2, 2026


Vulnerability identifier: #VU146670
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78587
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service of agent upload operations.

The vulnerability exists due to incorrect authorization in Fleet Server multi-part data upload operations when verifying session ownership during uploads. A remote user can interfere with active upload sessions belonging to other enrolled agents to cause a denial of service of agent upload operations.

All configurations are affected.


Affected software

Fleet Server

How to mitigate CVE-2026-78587

Install security update from vendor's website.

Fleet Server - addressed in versions 8.19.16, 9.3.5, 9.4.2

External References

Related Security Bulletins