vciy

CVEs we hold for Fleetdm

Records whose assigning authority named Fleetdm as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-54245Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet databasefleetdm fleet
CVE-2026-48786Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointfleetdm fleet
CVE-2026-46371Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpointfleetdm fleet
CVE-2026-46370Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpointfleetdm fleet
CVE-2026-46356Fleet: IP spoofing allows bypassing API rate limitingfleetdm fleet
CVE-2026-41262Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpointfleetdm fleet
CVE-2026-34391Fleet Vulnerable to Windows MDM cross-device command disclosurefleetdm fleet
CVE-2026-34389Fleet's user account creation via invite does not enforce invited email addressfleetdm fleet
CVE-2026-34388Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpointfleetdm fleet
CVE-2026-34387Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scriptsfleetdm fleet
CVE-2026-34386Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global adminfleetdm fleet
CVE-2026-34385Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the databasefleetdm fleet
CVE-2026-29180Fleet's team maintainer can transfer hosts from any team via missing source team authorizationfleetdm fleet
CVE-2026-27806Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbitfleetdm fleet
CVE-2026-27465Fleet: Sensitive Google Calendar credentials disclosed to low-privileged usersfleetdm fleet
CVE-2026-26191Fleet vulnerable to OS command injection in software packagesfleetdm fleet
CVE-2026-26186Fleet has a SQL injection via backtick escape in ORDER BY parameterfleetdm fleet
CVE-2026-26062Fleet server may terminate unexpectedly when handling certain gRPC requestsfleetdm fleet
CVE-2026-26061Fleet's unbounded request body read allows remote Denial of Servicefleetdm fleet
CVE-2026-26060Fleet: Password reset tokens remain valid after password change for 24 hoursfleetdm fleet
CVE-2026-25963Fleet: Authorization Bypass in certificate template batch deletion for team administratorsfleetdm fleet
CVE-2026-24899Fleet Windows MDM Azure AD JWT Authentication Bypassfleetdm fleet
CVE-2026-24004Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpointfleetdm fleet
CVE-2026-24000Fleet has a rate limiting bypass via untrusted client IP headersfleetdm fleet
CVE-2026-23999Fleet: Device lock PIN can be predicted if lock time is knownfleetdm fleet
CVE-2026-23998Fleet has a Windows MDM management endpoint authentication bypassfleetdm fleet
CVE-2026-23518Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollmentfleetdm fleet
CVE-2026-23517Fleet has an Access Control vulnerability in debug/pprof endpointsfleetdm fleet
CVE-2026-22808Fleet Windows MDM endpoint has a Cross-site Scripting vulnerabilityfleetdm fleet
CVE-2025-27509SAML authentication vulnerability due to improper SAML response validationfleetdm fleet
CVE-2022-24841Improper Authorization in github.com/fleetdm/fleetfleetdm fleet
CVE-2022-23600Limited ability to spoof SAML authentication with missing audience verificationfleetdm fleet
CVE-2021-21296Denial-of-service in Fleetfleetdm fleet
CVE-2020-26276SAML authentication vulnerability in Fleetfleetdm fleet

34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.