Fleetdm Fleet vulnerabilities
39 known vulnerabilities affecting fleetdm/fleet.
Total CVEs
39
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM15LOW2
Vulnerabilities
Page 2 of 2
CVE-2026-27806P3HIGHCVSS 7.8fixed in 4.81.12026-04-08
CVE-2026-27806 [HIGH] CWE-78 CVE-2026-27806: Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk e
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the password is inserted into Tcl brace-quoted send {%s}, a
nvd
CVE-2026-27465P3MEDIUMCVSS 6.5fixed in 4.80.12026-02-26
CVE-2026-27465 [MEDIUM] CWE-201 CVE-2026-27465: Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fle
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorized access to Google Calendar resources associated with the service account. Fleet returns configu
nvd
CVE-2026-34388P3HIGHCVSS 7.5fixed in 4.81.02026-03-27
CVE-2026-34388 [HIGH] CWE-703 CVE-2026-34388: Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The server terminates immediately, disrupting all connected hosts, MDM enrollments, and API consumers. Versio
nvd
CVE-2026-48786P3MEDIUMCVSS 6.5fixed in 4.87.02026-08-26
CVE-2026-48786 [MEDIUM] CWE-200 CVE-2026-48786: Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, th
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-privilege observer-class users. Other team-facing endpoints mask these fiel
nvd
CVE-2026-34389P3MEDIUMCVSS 6.5fixed in 4.81.1fixed in 4.81.02026-03-27
CVE-2026-34389 [MEDIUM] CWE-287 CVE-2026-34389: Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the us
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token could create an account under an arbitrary email address
nvd
CVE-2026-25963P3MEDIUMCVSS 6.5fixed in 4.80.12026-02-26
CVE-2026-25963 [MEDIUM] CWE-863 CVE-2026-25963: Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. Fleet supports certificate templates that are scoped to individual teams. In
nvd
CVE-2026-26062P3MEDIUMCVSS 6.5fixed in 4.81.02026-05-14
CVE-2026-26062 [MEDIUM] CWE-20 CVE-2026-26062: Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-o
Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input values were not handled gracefully, which could cause the Fleet server process to terminate while processing an authenticated request from
nvd
CVE-2026-46371P3MEDIUMCVSS 6.5fixed in 4.84.22026-08-26
CVE-2026-46371 [MEDIUM] CWE-89 CVE-2026-46371: Fleet is an open-source device management platform built on osquery. In versions up to and including
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined database tables, including host enrollment secrets and
nvd
CVE-2026-24000P3MEDIUMCVSS 5.3fixed in 4.80.12026-05-14
CVE-2026-24000 [MEDIUM] CWE-290 CVE-2026-24000: Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-suppl
Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass per-IP rate limiting controls. Fleet determines a client’s public IP addr
nvd
CVE-2026-46370P3MEDIUMCVSS 6.5fixed in 4.84.22026-08-26
CVE-2026-46370 [MEDIUM] CWE-89 CVE-2026-46370: Fleet is an open-source device management platform built on osquery. In versions up to and including
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-order oracle. The endpoint accepted a user-supplied
nvd
CVE-2022-23600P3MEDIUMCVSS 6.5fixed in 4.9.12022-02-04
CVE-2022-23600 [MEDIUM] CWE-287 CVE-2022-23600: fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limite
fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1. A malicious or compromised Service Provider (SP) could reuse the SAML response to log into Fleet as a user --
nvd
CVE-2026-101047P3MEDIUMCVSS 5.3fixed in 4.87.02026-09-27
CVE-2026-101047 [MEDIUM] CWE-862 CVE-2026-101047: Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authenticat
nvd
CVE-2026-24004P3MEDIUMCVSS 5.3fixed in 4.80.12026-02-26
CVE-2026-24004 [MEDIUM] CWE-862 CVE-2026-24004: Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fle
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal of individual Android devices from Fleet management. If Android MDM is enabled, an attacker could sen
nvd
CVE-2026-22808P3MEDIUMCVSS 5.4fixed in 4.53.3≥ 4.75.0, < 4.75.2+6 more2026-01-21
CVE-2026-22808 [MEDIUM] CWE-79 CVE-2026-22808: fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4
fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorage. This could allow unauthorized access to Fleet, inc
nvd
CVE-2026-23999P4MEDIUMCVSS 5.5fixed in 4.80.12026-02-26
CVE-2026-23999 [MEDIUM] CWE-330 CVE-2026-23999: Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device
Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, the resulting PIN could potentially be derived if the approximate time the device was locked is known.
nvd
CVE-2026-103265P4MEDIUMCVSS 4.3fixed in 4.89.02026-10-01
CVE-2026-103265 [MEDIUM] CWE-863 CVE-2026-103265: Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in th
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
nvd
CVE-2026-41262P4MEDIUMCVSS 4.3fixed in 4.85.02026-08-26
CVE-2026-41262 [MEDIUM] CWE-863 CVE-2026-41262: Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, th
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authenticated user with observer-level access on any single team to read the full details of policies belong
nvd
CVE-2026-101046P4LOWCVSS 3.1fixed in 4.89.02026-09-27
CVE-2026-101046 [LOW] CWE-89 CVE-2026-101046: Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api
Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToSQL interpolated the caller-supplied sort/order key into the SQL ORDER BY clause without an allowlist, so an authenti
nvd
CVE-2021-21296P4LOWCVSS 2.7fixed in 3.7.02021-02-10
CVE-2021-21296 [LOW] CWE-400 CVE-2021-21296: Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a vali
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this vulnerability to be low given the requirement
nvd
← Previous2 / 2