CVE-2026-72657: Authorization Bypass Through User-Controlled Key in Fleet Server Leading to Information Disclosure
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72657?
The severity of CVE-2026-72657 is medium with a score of 6.5.
What risk does CVE-2026-72657 pose?
CVE-2026-72657 poses a risk level of 38, indicating a potential for significant impact if exploited.
How do I fix CVE-2026-72657?
To fix CVE-2026-72657, ensure proper validation of user-controlled variables in Fleet Server to prevent unauthorized access.
What type of vulnerability is CVE-2026-72657?
CVE-2026-72657 is an authorization bypass vulnerability that can lead to information disclosure.
What systems are affected by CVE-2026-72657?
CVE-2026-72657 specifically affects the Fleet Server application.