PatchSiren

fleetdm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM fleetdm CVE published 2026-09-27

CVE-2026-101047

CVE-2026-101047 debrief: Fleet before 4.87.0 has unauthenticated iOS app download via predictable URLs. This vulnerability impacts enterprise tier users, allowing read-only disclosure of in-house IPA binaries and their metadata. Defenders should assess exposure and prioritize remediation to prevent unauthorized access. The issue is limited to enterprise tier users, with no privilege escalation or write ac [truncated]

LOW fleetdm CVE published 2026-09-27

CVE-2026-101046

CVE-2026-101046 is an SQL injection vulnerability in Fleet before 4.89.0, specifically in the activity list endpoints. An authenticated user with read access to Activity could order results by arbitrary columns, allowing inference of values in the activity_past table that are not otherwise returned in these responses. The impact is read-only and bounded to specific columns. Fixed in 4.89.0.

HIGH fleetdm CVE published 2026-09-27

CVE-2026-101045

CVE-2026-101045 debrief: Fleet's macOS app install and uninstall scripts generated before 2026-08-19 were vulnerable to OS command injection via Homebrew cask metadata. An attacker could inject shell metacharacters to execute arbitrary commands as root on managed macOS hosts. The issue was fixed in Fleet's ingestion pipeline on 2026-08-19 and is included in Fleet v4.92.0.

HIGH fleetdm CVE published 2026-08-26

CVE-2026-54245

A SQL injection vulnerability exists in Fleet Premium's Okta conditional access integration prior to version 4.86.2. An attacker controlling a single enrolled host can inject malicious SQL, potentially reading or modifying arbitrary data in the Fleet database, including extracting session tokens to gain administrator access and execute scripts on enrolled hosts.

MEDIUM fleetdm CVE published 2026-08-26

CVE-2026-46371

CVE-2026-46371 debrief: authenticated users with Observer role could extract sensitive values from Fleet's database, including host enrollment secrets and Apple Push Notification Service tokens, via a sort-order oracle in the Apple MDM commands listing endpoint. This vulnerability allows low-privilege users to potentially impersonate enrolled hosts and access sensitive data. Defenders should assess exposu [truncated]

MEDIUM fleetdm CVE published 2026-08-26

CVE-2026-46370

CVE-2026-46370 debrief: authenticated users with Observer role could extract host enrollment secrets via labels host-listing endpoint. The vulnerability allows an attacker to impersonate enrolled hosts, submit fabricated query results and inventory, retrieve pending scripts and MDM commands, and poison compliance and policy results across the deployment. Defenders should assess exposure and prioritize rem [truncated]

MEDIUM fleetdm CVE published 2026-08-26

CVE-2026-48786

CVE-2026-48786 debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T19:16:50.643Z and has not been modified since then. This vulnerability affects Fleet device management platforms, specifically versions prior to 4.87.0, where the target search endpoint returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-p [truncated]

MEDIUM fleetdm CVE published 2026-08-26

CVE-2026-41262

CVE-2026-41262 debrief: In Fleet versions prior to 4.85.0, an authenticated user with observer-level access on any single team can read full details of policies belonging to any other team due to a failure in verifying team ownership of the requested policy. This issue allows for the enumeration of policy IDs to access security-monitoring strategies and compliance posture across team boundaries.

MEDIUM Fleetdm CVE published 2026-05-14

CVE-2026-46356

CVE-2026-46356 affects Fleet versions before 4.80.1. Fleet’s client-IP extraction logic accepted forwarded IP headers without verifying that they came from a trusted proxy, which let unauthenticated attackers vary those headers and evade per-IP rate limits and IP bans. The practical risk is increased exposure of public Fleet deployments to brute-force login and credential-stuffing attempts, especially whe [truncated]

MEDIUM Fleetdm CVE published 2026-05-14

CVE-2026-26191

CVE-2026-26191 is a Fleet device-management vulnerability in the software installer pipeline. If a crafted software package is uploaded and later uninstalled, unsanitized metadata from that package can be inserted into auto-generated uninstall scripts. When those scripts run on managed endpoints, an attacker could trigger unintended command execution with elevated privileges: root on macOS/Linux or SYSTEM [truncated]

HIGH fleetdm CVE published 2026-05-14

CVE-2026-24899

Fleet's Windows MDM enrollment flow prior to version 4.82.0 fails to validate JWT audience (`aud`) and issuer (`iss`) claims when verifying Azure AD authentication tokens. The application uses Microsoft's multi-tenant JWKS endpoint for signature validation but accepts tokens from any Azure AD tenant, not just the configured tenant. An attacker with access to any valid Azure AD tenant can obtain a Microsof [truncated]