Vulnerability record · CVE-2023-46667 · published 26 October 2023
CVE-2023-46667: Elastic fleet server sensitive information in log file vulnerability
Elastic · Fleet Server
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.
Description
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://discuss.elastic.co/t/fleet-server-v8-10-3-security-update/344737 | Release Notes |
| https://www.elastic.co/community/security | Vendor Advisory |
| https://discuss.elastic.co/t/fleet-server-v8-10-3-security-update/344737 | Release Notes |
| https://www.elastic.co/community/security | Vendor Advisory |
Track CVE-2023-46667 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46667), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.