PatchSiren cyber security CVE debrief
CVE-2026-46370 fleetdm CVE debrief
CVE-2026-46370 debrief: authenticated users with Observer role could extract host enrollment secrets via labels host-listing endpoint. The vulnerability allows an attacker to impersonate enrolled hosts, submit fabricated query results and inventory, retrieve pending scripts and MDM commands, and poison compliance and policy results across the deployment. Defenders should assess exposure and prioritize remediation to prevent potential security consequences. The issue is fixed in version 4.84.2.
- Vendor
- fleetdm
- Product
- fleet
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for Fleet instances, security teams, and administrators of device management platforms should assess exposure and prioritize remediation to prevent potential security consequences. This includes verifying exposure, remediating vulnerable instances, and monitoring for suspicious activity.
Why it matters
CVE-2026-46370 allows authenticated users with Observer role to extract host enrollment secrets, potentially leading to impersonation of enrolled hosts and other security consequences. Defenders should prioritize verifying exposure and remediating vulnerable Fleet instances.
- Impersonation of enrolled hosts
- Submission of fabricated query results and inventory
- Retrieval of pending scripts and MDM commands
- Poisoning of compliance and policy results
Technical summary
CVE-2026-46370 is a vulnerability in the Fleet device management platform that allows an authenticated user with the Observer role to extract host enrollment secrets through a sort-order oracle in the labels host-listing endpoint. The vulnerability can lead to impersonation of enrolled hosts, submission of fabricated query results and inventory, retrieval of pending scripts and MDM commands, and poisoning of compliance and policy results. The issue is fixed in version 4.84.2, and defenders should prioritize verifying exposure and remediating vulnerable Fleet instances.
Defensive priority
Defenders should prioritize verifying exposure and remediating vulnerable Fleet instances
Recommended defensive actions
- Verify Fleet instance exposure and upgrade to version 4.84.2 or later
- Restrict access to the labels host-listing endpoint
- Monitor for suspicious activity on the Fleet server
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, which was fixed in Fleet version 4.84.2. Evidence is limited to public CVE and NVD records. Defenders should verify exposure and remediate vulnerable Fleet instances according to vendor guidance. The vulnerability affects Fleet instances up to and including version 4.84.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46370 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46370
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46370 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46370
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/fleetdm/fleet/security/advisories/GHSA-vxm7-9x8v-8gm4
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.