AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72670

HIGH · CVSS 7.7 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A vulnerability exists that allows a lower privileged user, with only read access to agent policies, to access the complete configuration of a Fleet proxy, which typically requires higher privileges. This exposure could lead to unauthorized access to sensitive information, including proxy authentication credentials and private key material. Organizations utilizing Fleet proxies should prioritize remediation to prevent potential data breaches and unauthorized access.

CVE
CVE-2026-72670
Severity
HIGH
CVSS
7.7
EPSS
0.30%

Original NVD Description

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.