Fleetdm / Fleet
39 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-103265 | Fleet before 4.89.0 Information Disclosure via MDM Command Results | MEDIUM | 5.3 | Oct 1, 2026 |
| CVE-2026-103264 | Fleet before 4.87.0 Authentication Bypass via Device Identifiers | CRITICAL | 9.3 | Oct 1, 2026 |
| CVE-2026-101047 | Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs | MEDIUM | 6.9 | Sep 27, 2026 |
| CVE-2026-101046 | Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints | LOW | 2.3 | Sep 27, 2026 |
| CVE-2026-101045 | Fleet Homebrew Cask OS Command Injection via Metadata | HIGH | 8.9 | Sep 27, 2026 |
| CVE-2026-54245 | Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database | HIGH | 7.6 | Aug 26, 2026 |
| CVE-2026-46371 | Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-46370 | Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-41262 | Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint | MEDIUM | 4.3 | Aug 26, 2026 |
| CVE-2026-48786 | Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-46356 | Fleet: IP spoofing allows bypassing API rate limiting | MEDIUM | 6.9 | May 14, 2026 |
| CVE-2026-26191 | Fleet vulnerable to OS command injection in software packages | MEDIUM | 6.0 | May 14, 2026 |
| CVE-2026-26062 | Fleet server may terminate unexpectedly when handling certain gRPC requests | HIGH | 8.7 | May 14, 2026 |
| CVE-2026-24899 | Fleet Windows MDM Azure AD JWT Authentication Bypass | HIGH | 8.2 | May 14, 2026 |
| CVE-2026-24000 | Fleet has a rate limiting bypass via untrusted client IP headers | MEDIUM | 6.9 | May 14, 2026 |
| CVE-2026-23998 | Fleet has a Windows MDM management endpoint authentication bypass | HIGH | 8.2 | May 14, 2026 |
| CVE-2026-27806 | Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit | HIGH | 7.8 | Apr 8, 2026 |
| CVE-2026-34391 | Fleet Vulnerable to Windows MDM cross-device command disclosure | MEDIUM | 6.6 | Mar 27, 2026 |
| CVE-2026-34389 | Fleet's user account creation via invite does not enforce invited email address | MEDIUM | 4.9 | Mar 27, 2026 |
| CVE-2026-34388 | Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint | MEDIUM | 6.6 | Mar 27, 2026 |
| CVE-2026-34387 | Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts | MEDIUM | 5.7 | Mar 27, 2026 |
| CVE-2026-34386 | Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin | MEDIUM | 6.3 | Mar 27, 2026 |
| CVE-2026-34385 | Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database | MEDIUM | 6.2 | Mar 27, 2026 |
| CVE-2026-29180 | Fleet's team maintainer can transfer hosts from any team via missing source team authorization | MEDIUM | 4.9 | Mar 27, 2026 |
| CVE-2026-26061 | Fleet's unbounded request body read allows remote Denial of Service | HIGH | 8.7 | Mar 27, 2026 |
Showing 1 to 25 of 39 CVEs