These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-101047 debrief: Fleet before 4.87.0 has unauthenticated iOS app download via predictable URLs. This vulnerability impacts enterprise tier users, allowing read-only disclosure of in-house IPA binaries and their metadata. Defenders should assess exposure and prioritize remediation to prevent unauthorized access. The issue is limited to enterprise tier users, with no privilege escalation or write ac [truncated]
CVE-2026-101046 is an SQL injection vulnerability in Fleet before 4.89.0, specifically in the activity list endpoints. An authenticated user with read access to Activity could order results by arbitrary columns, allowing inference of values in the activity_past table that are not otherwise returned in these responses. The impact is read-only and bounded to specific columns. Fixed in 4.89.0.
CVE-2026-101045 debrief: Fleet's macOS app install and uninstall scripts generated before 2026-08-19 were vulnerable to OS command injection via Homebrew cask metadata. An attacker could inject shell metacharacters to execute arbitrary commands as root on managed macOS hosts. The issue was fixed in Fleet's ingestion pipeline on 2026-08-19 and is included in Fleet v4.92.0.
A SQL injection vulnerability exists in Fleet Premium's Okta conditional access integration prior to version 4.86.2. An attacker controlling a single enrolled host can inject malicious SQL, potentially reading or modifying arbitrary data in the Fleet database, including extracting session tokens to gain administrator access and execute scripts on enrolled hosts.
CVE-2026-46371 debrief: authenticated users with Observer role could extract sensitive values from Fleet's database, including host enrollment secrets and Apple Push Notification Service tokens, via a sort-order oracle in the Apple MDM commands listing endpoint. This vulnerability allows low-privilege users to potentially impersonate enrolled hosts and access sensitive data. Defenders should assess exposu [truncated]
CVE-2026-46370 debrief: authenticated users with Observer role could extract host enrollment secrets via labels host-listing endpoint. The vulnerability allows an attacker to impersonate enrolled hosts, submit fabricated query results and inventory, retrieve pending scripts and MDM commands, and poison compliance and policy results across the deployment. Defenders should assess exposure and prioritize rem [truncated]
CVE-2026-48786 debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T19:16:50.643Z and has not been modified since then. This vulnerability affects Fleet device management platforms, specifically versions prior to 4.87.0, where the target search endpoint returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-p [truncated]
CVE-2026-41262 debrief: In Fleet versions prior to 4.85.0, an authenticated user with observer-level access on any single team can read full details of policies belonging to any other team due to a failure in verifying team ownership of the requested policy. This issue allows for the enumeration of policy IDs to access security-monitoring strategies and compliance posture across team boundaries.
CVE-2026-46356 affects Fleet versions before 4.80.1. Fleet’s client-IP extraction logic accepted forwarded IP headers without verifying that they came from a trusted proxy, which let unauthenticated attackers vary those headers and evade per-IP rate limits and IP bans. The practical risk is increased exposure of public Fleet deployments to brute-force login and credential-stuffing attempts, especially whe [truncated]
CVE-2026-26191 is a Fleet device-management vulnerability in the software installer pipeline. If a crafted software package is uploaded and later uninstalled, unsanitized metadata from that package can be inserted into auto-generated uninstall scripts. When those scripts run on managed endpoints, an attacker could trigger unintended command execution with elevated privileges: root on macOS/Linux or SYSTEM [truncated]
Fleet's Windows MDM enrollment flow prior to version 4.82.0 fails to validate JWT audience (`aud`) and issuer (`iss`) claims when verifying Azure AD authentication tokens. The application uses Microsoft's multi-tenant JWKS endpoint for signature validation but accepts tokens from any Azure AD tenant, not just the configured tenant. An attacker with access to any valid Azure AD tenant can obtain a Microsof [truncated]