Fleetdm
Fleetdm Fleet: vulnerabilidades y CVE
Fleetdm Fleet tiene 31 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses26
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103265 | Media (5.3) | 0.20% | — | 1 oct 2026 | Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared… |
| CVE-2026-101045 | Alta (8.9) | 0.75% | — | 27 sept 2026 | Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites… |
| CVE-2026-46356 | Media (6.9) | 0.39% | — | 14 may 2026 | Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This… |
| CVE-2026-26191 | Media (6) | 0.94% | — | 14 may 2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux)… |
| CVE-2026-26062 | Alta (8.7) | 0.54% | — | 14 may 2026 | Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input… |
| CVE-2026-24899 | Alta (8.2) | 0.38% | — | 14 may 2026 | Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet… |
| CVE-2026-24000 | Media (6.9) | 0.43% | — | 14 may 2026 | Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and… |
| CVE-2026-23998 | Alta (8.2) | 0.21% | — | 14 may 2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In… |
| CVE-2026-27806 | Alta (7.8) | 0.11% | — | 8 abr 2026 | Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a… |
| CVE-2026-34391 | Media (6.6) | 0.26% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices,… |
| CVE-2026-34389 | Media (4.9) | 0.30% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email… |
| CVE-2026-34388 | Media (6.6) | 0.46% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an… |
| CVE-2026-34387 | Media (5.7) | 1.8% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or… |
| CVE-2026-34386 | Media (6.3) | 0.44% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to… |
| CVE-2026-34385 | Media (6.2) | 0.25% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate… |
| CVE-2026-29180 | Media (4.9) | 0.42% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team,… |
| CVE-2026-26061 | Alta (8.7) | 0.48% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could… |
| CVE-2026-26060 | Media (6) | 0.46% | — | 27 mar 2026 | Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their… |
| CVE-2026-27465 | Baja (1.3) | 0.39% | — | 26 feb 2026 | Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with… |
| CVE-2026-25963 | Baja (1.2) | 0.35% | — | 26 feb 2026 | Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates… |
| CVE-2026-24004 | Baja (1.7) | 0.27% | — | 26 feb 2026 | Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may… |
| CVE-2026-23999 | Baja (0.6) | 0.13% | — | 26 feb 2026 | Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or… |
| CVE-2026-26186 | Media (5.1) | 0.56% | — | 26 feb 2026 | Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the `order_key` query parameter. Due to… |
| CVE-2026-23518 | Crítica (9.3) | 0.26% | — | 21 ene 2026 | Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged… |
| CVE-2026-23517 | Media (6.3) | 0.29% | — | 21 ene 2026 | Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints… |
| CVE-2026-22808 | Media (5.5) | 0.25% | — | 21 ene 2026 | fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a… |
| CVE-2025-27509 | Crítica (9.3) | 0.67% | — | 6 mar 2025 | fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new… |
| CVE-2022-24841 | Alta (8.1) | 0.85% | — | 18 abr 2022 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams… |
| CVE-2022-23600 | Media (6.5) | 0.90% | — | 4 feb 2022 | fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in… |
| CVE-2021-21296 | Baja (2.7) | 1.9% | — | 10 feb 2021 | Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.