CVE-2026-34387
- EPSS 1.28%
- Veröffentlicht 27.03.2026 18:31:27
- Zuletzt bearbeitet 07.04.2026 21:15:54
Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hos...
CVE-2026-34386
- EPSS 0.32%
- Veröffentlicht 27.03.2026 18:30:10
- Zuletzt bearbeitet 02.04.2026 17:04:41
Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurat...
CVE-2026-34385
- EPSS 0.2%
- Veröffentlicht 27.03.2026 18:29:05
- Zuletzt bearbeitet 07.04.2026 21:15:47
Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or modify the co...
CVE-2026-29180
- EPSS 0.32%
- Veröffentlicht 27.03.2026 18:27:15
- Zuletzt bearbeitet 31.03.2026 18:50:35
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. On...
CVE-2026-26061
- EPSS 0.43%
- Veröffentlicht 27.03.2026 18:23:49
- Zuletzt bearbeitet 31.03.2026 18:51:33
Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending larg...
CVE-2026-26060
- EPSS 0.34%
- Veröffentlicht 27.03.2026 18:22:43
- Zuletzt bearbeitet 31.03.2026 16:23:48
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale passw...
CVE-2026-27465
- EPSS 0.24%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 02.03.2026 15:48:25
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauth...
CVE-2026-25963
- EPSS 0.19%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 27.02.2026 16:05:58
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within t...
CVE-2026-24004
- EPSS 0.26%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 02.03.2026 15:49:08
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal ...
CVE-2026-23999
- EPSS 0.12%
- Veröffentlicht 26.02.2026 03:16:04
- Zuletzt bearbeitet 02.03.2026 15:47:56
Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, th...