PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46370 fleetdm CVE debrief

CVE-2026-46370 debrief: authenticated users with Observer role could extract host enrollment secrets via labels host-listing endpoint. The vulnerability allows an attacker to impersonate enrolled hosts, submit fabricated query results and inventory, retrieve pending scripts and MDM commands, and poison compliance and policy results across the deployment. Defenders should assess exposure and prioritize remediation to prevent potential security consequences. The issue is fixed in version 4.84.2.

Vendor
fleetdm
Product
fleet
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-09
Advisory published
2026-08-26
Advisory updated
2026-09-09

Who should care

Defenders responsible for Fleet instances, security teams, and administrators of device management platforms should assess exposure and prioritize remediation to prevent potential security consequences. This includes verifying exposure, remediating vulnerable instances, and monitoring for suspicious activity.

Why it matters

CVE-2026-46370 allows authenticated users with Observer role to extract host enrollment secrets, potentially leading to impersonation of enrolled hosts and other security consequences. Defenders should prioritize verifying exposure and remediating vulnerable Fleet instances.

  • Impersonation of enrolled hosts
  • Submission of fabricated query results and inventory
  • Retrieval of pending scripts and MDM commands
  • Poisoning of compliance and policy results

Technical summary

CVE-2026-46370 is a vulnerability in the Fleet device management platform that allows an authenticated user with the Observer role to extract host enrollment secrets through a sort-order oracle in the labels host-listing endpoint. The vulnerability can lead to impersonation of enrolled hosts, submission of fabricated query results and inventory, retrieval of pending scripts and MDM commands, and poisoning of compliance and policy results. The issue is fixed in version 4.84.2, and defenders should prioritize verifying exposure and remediating vulnerable Fleet instances.

Defensive priority

Defenders should prioritize verifying exposure and remediating vulnerable Fleet instances

Recommended defensive actions

  • Verify Fleet instance exposure and upgrade to version 4.84.2 or later
  • Restrict access to the labels host-listing endpoint
  • Monitor for suspicious activity on the Fleet server
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, which was fixed in Fleet version 4.84.2. Evidence is limited to public CVE and NVD records. Defenders should verify exposure and remediate vulnerable Fleet instances according to vendor guidance. The vulnerability affects Fleet instances up to and including version 4.84.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46370 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46370

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46370 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46370

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.