CVE-2026-27806
- EPSS 0.01%
- Veröffentlicht 08.04.2026 17:40:24
- Zuletzt bearbeitet 14.04.2026 19:31:32
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via ex...
CVE-2026-34391
- EPSS 0.02%
- Veröffentlicht 27.03.2026 19:19:48
- Zuletzt bearbeitet 02.04.2026 19:42:08
Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configura...
CVE-2026-34389
- EPSS 0.03%
- Veröffentlicht 27.03.2026 19:18:19
- Zuletzt bearbeitet 02.04.2026 19:41:09
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. A...
CVE-2026-34388
- EPSS 0.06%
- Veröffentlicht 27.03.2026 19:13:00
- Zuletzt bearbeitet 02.04.2026 19:34:17
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The s...
CVE-2026-34387
- EPSS 0.13%
- Veröffentlicht 27.03.2026 18:31:27
- Zuletzt bearbeitet 07.04.2026 21:15:54
Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hos...
CVE-2026-34386
- EPSS 0.03%
- Veröffentlicht 27.03.2026 18:30:10
- Zuletzt bearbeitet 02.04.2026 17:04:41
Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurat...
CVE-2026-34385
- EPSS 0.02%
- Veröffentlicht 27.03.2026 18:29:05
- Zuletzt bearbeitet 07.04.2026 21:15:47
Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or modify the co...
CVE-2026-29180
- EPSS 0.05%
- Veröffentlicht 27.03.2026 18:27:15
- Zuletzt bearbeitet 31.03.2026 18:50:35
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. On...
CVE-2026-26061
- EPSS 0.06%
- Veröffentlicht 27.03.2026 18:23:49
- Zuletzt bearbeitet 31.03.2026 18:51:33
Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending larg...
CVE-2026-26060
- EPSS 0.05%
- Veröffentlicht 27.03.2026 18:22:43
- Zuletzt bearbeitet 31.03.2026 16:23:48
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale passw...