THREAT OPS › Threat News › [NVD] CVE-2026-72670 (HIGH 7.7) — A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials a
[NVD] CVE-2026-72670 (HIGH 7.7) — A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials a
CVE-2026-72670 CVSS: 7.7 HIGH Published: 2026-08-13T20:17:27.530
A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be author
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-72670cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72670