CVE-2026-23999
- EPSS 0.02%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 02.03.2026 15:47:56
Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, th...
CVE-2026-24004
- EPSS 0.09%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 02.03.2026 15:49:08
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal ...
CVE-2026-25963
- EPSS 0.04%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 27.02.2026 16:05:58
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within t...
CVE-2026-27465
- EPSS 0.04%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 02.03.2026 15:48:25
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauth...
CVE-2026-26186
- EPSS 0.05%
- Veröffentlicht 26.02.2026 00:16:23
- Zuletzt bearbeitet 02.03.2026 15:45:35
Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the `order_key` query parameter. Due to unsafe use of `goqu.I()` when const...
CVE-2026-23518
- EPSS 0.05%
- Veröffentlicht 21.01.2026 21:50:47
- Zuletzt bearbeitet 27.02.2026 16:14:59
Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not prope...
CVE-2026-23517
- EPSS 0.05%
- Veröffentlicht 21.01.2026 21:45:34
- Zuletzt bearbeitet 27.02.2026 16:16:14
Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-pr...
CVE-2026-22808
- EPSS 0.12%
- Veröffentlicht 21.01.2026 21:18:26
- Zuletzt bearbeitet 18.02.2026 15:31:03
fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authenti...
CVE-2025-27509
- EPSS 0.19%
- Veröffentlicht 06.03.2025 19:15:27
- Zuletzt bearbeitet 06.03.2025 19:15:27
fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-...
CVE-2022-24841
- EPSS 0.21%
- Veröffentlicht 18.04.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:12
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accou...