fleetdm fleet

10 known vulnerabilities in fleetdm fleet, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-103265 CVSS 5.3 medium Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint…
  • CVE-2026-103264 CVSS 9.3 critical Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials…
  • CVE-2026-101047 CVSS 6.9 medium Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only)…
  • CVE-2026-101046 CVSS 2.3 low Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET…
  • CVE-2026-101045 CVSS 8.9 high Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before…
  • CVE-2026-54245 CVSS 7.6 high Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration…
  • CVE-2026-46371 CVSS 6.5 medium Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands…
  • CVE-2026-46370 CVSS 6.5 medium Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing…
  • CVE-2026-48786 CVSS 6.5 medium Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST…
  • CVE-2026-41262 CVSS 4.3 medium Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET…