CVE-2026-46356
- EPSS 0.28%
- Veröffentlicht 14.05.2026 19:03:50
- Zuletzt bearbeitet 18.05.2026 15:27:53
Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login atte...
CVE-2026-26191
- EPSS 0.77%
- Veröffentlicht 14.05.2026 19:02:12
- Zuletzt bearbeitet 18.05.2026 14:05:02
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed...
CVE-2026-26062
- EPSS 0.37%
- Veröffentlicht 14.05.2026 19:00:21
- Zuletzt bearbeitet 18.05.2026 14:09:38
Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input values were not handled gracefully, ...
CVE-2026-24899
- EPSS 0.38%
- Veröffentlicht 14.05.2026 18:58:26
- Zuletzt bearbeitet 26.05.2026 14:44:57
Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures using Micros...
CVE-2026-24000
- EPSS 0.43%
- Veröffentlicht 14.05.2026 18:56:39
- Zuletzt bearbeitet 15.05.2026 20:05:44
Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their app...
CVE-2026-23998
- EPSS 0.21%
- Veröffentlicht 14.05.2026 18:48:38
- Zuletzt bearbeitet 15.05.2026 18:08:13
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this cou...
CVE-2026-27806
- EPSS 0.11%
- Veröffentlicht 08.04.2026 17:40:24
- Zuletzt bearbeitet 14.04.2026 19:31:32
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via ex...
CVE-2026-34391
- EPSS 0.16%
- Veröffentlicht 27.03.2026 19:19:48
- Zuletzt bearbeitet 02.04.2026 19:42:08
Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configura...
CVE-2026-34389
- EPSS 0.18%
- Veröffentlicht 27.03.2026 19:18:19
- Zuletzt bearbeitet 02.04.2026 19:41:09
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. A...
CVE-2026-34388
- EPSS 0.26%
- Veröffentlicht 27.03.2026 19:13:00
- Zuletzt bearbeitet 02.04.2026 19:34:17
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The s...