PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54245 fleetdm CVE debrief

A SQL injection vulnerability exists in Fleet Premium's Okta conditional access integration prior to version 4.86.2. An attacker controlling a single enrolled host can inject malicious SQL, potentially reading or modifying arbitrary data in the Fleet database, including extracting session tokens to gain administrator access and execute scripts on enrolled hosts.

Vendor
fleetdm
Product
fleet
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-09
Advisory published
2026-08-26
Advisory updated
2026-09-09

Who should care

Defenders responsible for Fleet Premium instances with Okta conditional access integration should assess exposure and prioritize upgrading to version 4.86.2 or later. Security teams monitoring for suspicious activity and conducting inventory checks should also be aware of this vulnerability.

Why it matters

CVE-2026-54245 is a SQL injection vulnerability in Fleet Premium's Okta conditional access integration. Defenders should prioritize verifying exposure and upgrading to version 4.86.2 or later. The vulnerability allows an attacker controlling a single enrolled host to potentially read or modify arbitrary data in the Fleet database, extract session tokens, and gain administrator access to execute scripts on enrolled hosts. However, the exact scope of affected instances and potential exploitation remains unknown.

  • Potential extraction of stored session tokens
  • Possible elevation of privileges to global administrator
  • Execution of scripts on enrolled hosts
  • Verification of Fleet Premium instance vulnerability

Technical summary

The vulnerability exists in Fleet Premium's Okta conditional access integration due to improper parameterization of a database query using a host-supplied value. An attacker controlling a single enrolled host can inject malicious SQL, potentially reading or modifying arbitrary data in the Fleet database, including extracting session tokens to gain administrator access and execute scripts on enrolled hosts. This issue requires Fleet Premium with the Okta conditional access integration enabled and does not affect instances where it is not configured. The vulnerability is fixed in version 4.86.2.

Defensive priority

Defenders should prioritize verifying exposure of Fleet Premium instances with Okta conditional access integration and upgrading to version 4.86.2 or later. Inventory checks and monitoring for suspicious activity are recommended.

Recommended defensive actions

  • Verify Fleet Premium instances with Okta conditional access integration are upgraded to version 4.86.2 or later
  • Conduct inventory checks to identify potentially vulnerable instances
  • Monitor for suspicious activity related to Fleet database queries
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is confirmed in Fleet Premium versions prior to 4.86.2 with Okta conditional access integration enabled. The issue is fixed in version 4.86.2. However, the exact scope of affected instances and potential exploitation remains unknown.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54245 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54245

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54245 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54245

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.