CVE-2026-103265
- EPSS 0.2%
- Veröffentlicht 01.10.2026 10:42:06
- Zuletzt bearbeitet 08.10.2026 13:17:47
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across m...
CVE-2026-103264
- EPSS 0.32%
- Veröffentlicht 01.10.2026 10:42:06
- Zuletzt bearbeitet 08.10.2026 13:17:52
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secr...
CVE-2026-101047
- EPSS 0.24%
- Veröffentlicht 27.09.2026 17:02:35
- Zuletzt bearbeitet 07.10.2026 17:27:26
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requir...
CVE-2026-101046
- EPSS 0.17%
- Veröffentlicht 27.09.2026 17:02:35
- Zuletzt bearbeitet 07.10.2026 17:33:07
Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToSQL interpolat...
CVE-2026-101045
- EPSS 0.75%
- Veröffentlicht 27.09.2026 17:02:34
- Zuletzt bearbeitet 30.09.2026 18:18:13
Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask meta...
CVE-2026-54245
- EPSS 0.34%
- Veröffentlicht 26.08.2026 19:13:22
- Zuletzt bearbeitet 09.09.2026 21:09:13
Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a database query w...
CVE-2026-46371
- EPSS -
- Veröffentlicht 26.08.2026 19:06:12
- Zuletzt bearbeitet 09.09.2026 21:09:13
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observ...
CVE-2026-46370
- EPSS -
- Veröffentlicht 26.08.2026 18:54:31
- Zuletzt bearbeitet 09.09.2026 21:09:13
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role ...
CVE-2026-41262
- EPSS 0.18%
- Veröffentlicht 26.08.2026 18:32:30
- Zuletzt bearbeitet 09.09.2026 21:09:13
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authent...
CVE-2026-48786
- EPSS 0.25%
- Veröffentlicht 26.08.2026 18:25:09
- Zuletzt bearbeitet 09.09.2026 21:09:13
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bear...