Fleetdm

Fleet

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.28%
  • Veröffentlicht 27.03.2026 18:31:27
  • Zuletzt bearbeitet 07.04.2026 21:15:54

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hos...

  • EPSS 0.32%
  • Veröffentlicht 27.03.2026 18:30:10
  • Zuletzt bearbeitet 02.04.2026 17:04:41

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurat...

  • EPSS 0.2%
  • Veröffentlicht 27.03.2026 18:29:05
  • Zuletzt bearbeitet 07.04.2026 21:15:47

Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or modify the co...

  • EPSS 0.32%
  • Veröffentlicht 27.03.2026 18:27:15
  • Zuletzt bearbeitet 31.03.2026 18:50:35

Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. On...

  • EPSS 0.43%
  • Veröffentlicht 27.03.2026 18:23:49
  • Zuletzt bearbeitet 31.03.2026 18:51:33

Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending larg...

  • EPSS 0.34%
  • Veröffentlicht 27.03.2026 18:22:43
  • Zuletzt bearbeitet 31.03.2026 16:23:48

Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale passw...

  • EPSS 0.24%
  • Veröffentlicht 26.02.2026 03:16:04
  • Zuletzt bearbeitet 02.03.2026 15:48:25

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauth...

  • EPSS 0.19%
  • Veröffentlicht 26.02.2026 03:16:04
  • Zuletzt bearbeitet 27.02.2026 16:05:58

Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within t...

  • EPSS 0.26%
  • Veröffentlicht 26.02.2026 03:16:04
  • Zuletzt bearbeitet 02.03.2026 15:49:08

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal ...

  • EPSS 0.12%
  • Veröffentlicht 26.02.2026 03:16:04
  • Zuletzt bearbeitet 02.03.2026 15:47:56

Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, th...