Known Vulnerabilities for Fleet Server by Elastic
Listed below are 2 of the newest known vulnerabilities associated with "Fleet Server" by "Elastic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72677 json | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traver... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72676 json | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supp... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72657 json | Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulatin... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72648 json | Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-56151 json | Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An auth... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-56150 json | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive ... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2023-46667 json | An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fle... | 8.1 - HIGH | 2023-10-26 | 2023-11-03 |