Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.20% | — | Fleetdm FleetAI | 1/10/2026 | 1/10/2026 | Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device… | |
| Pendiente de análisis | Crítica (9.3) | 0.32% | — | FleetAI | 1/10/2026 | 1/10/2026 | Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device… | |
| Pendiente de análisis | Alta (8.8) | 0.27% | — | Suse Rancher FleetAI | 28/9/2026 | 29/9/2026 | A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for… | |
| Pendiente de análisis | Media (6.5) | 0.17% | — | Suse Rancher FleetAI | 28/9/2026 | 29/9/2026 | A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Suse Rancher FleetAI | 28/9/2026 | 29/9/2026 | A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller… | |
| Pendiente de análisis | Alta (7.1) | 0.17% | — | Suse Rancher FleetAI | 28/9/2026 | 29/9/2026 | A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | Suse Rancher FleetAI | 28/9/2026 | 29/9/2026 | A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the… | |
| Pendiente de análisis | Media (6.9) | 0.24% | — | FleetAI | 27/9/2026 | 30/9/2026 | Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot… | |
| Pendiente de análisis | Baja (2.3) | 0.17% | — | FleetAI | 27/9/2026 | 30/9/2026 | Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToSQL interpolated the caller-supplied sort/order key into the SQL ORDER BY clause… | |
| Pendiente de análisis | Alta (8.9) | 0.75% | — | Fleetdm FleetAI | 27/9/2026 | 30/9/2026 | Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask metadata containing shell metacharacters (for example $(...) command… | |
| Aplazada | Crítica (9.2) | 1.1% | — | Simove FleetmanagerAISimove SiplantAI | 8/9/2026 | 9/9/2026 | A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | FleetAI | 3/9/2026 | 5/9/2026 | A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: -… | |
| Analizada | Baja (3.1) | 0.29% | — | Elastic Fleet Server | 2/9/2026 | 3/9/2026 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions… | |
| Aplazada | Alta (7.6) | 0.57% | — | FleetAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a database query without proper parameterization, allowing an attacker who controls a… | |
| Aplazada | Media (6.5) | 0.37% | — | FleetAILinuxfoundation OsqueryAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined database tables,… | |
| Aplazada | Media (6.5) | 0.37% | — | FleetAILinuxfoundation OsqueryAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-order oracle. The… | |
| Aplazada | Media (6.5) | 0.44% | — | FleetAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-privilege observer-class users. Other… | |
| Aplazada | Media (4.3) | 0.30% | — | FleetAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authenticated user with observer-level access on any single team to read the… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Otto Fleet ManagerAI | 19/8/2026 | 28/8/2026 | A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker… | |
| Analizada | Media (6.5) | 0.39% | — | Elastic Fleet Server | 13/8/2026 | 4/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side… | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | FleetAI | 7/7/2026 | 8/7/2026 | A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could… | |
| Analizada | Alta (8.3) | 0.42% | — | Suse Rancher Fleet | 6/7/2026 | 9/7/2026 | Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system. | |
| Analizada | Media (5) | 0.35% | — | Suse Rancher Fleet | 6/7/2026 | 9/7/2026 | Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml… | |
| Analizada | Crítica (9.9) | 0.49% | — | Suse Rancher Fleet | 2/7/2026 | 6/7/2026 | Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants. | |
| Analizada | Alta (7.5) | 0.48% | — | Elastic Fleet Server | 1/7/2026 | 6/7/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable. |