CVEs we hold for Fleetdm
Records whose assigning authority named Fleetdm as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-54245Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet databasefleetdm fleet
CVE-2026-48786Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointfleetdm fleet
CVE-2026-46371Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpointfleetdm fleet
CVE-2026-46370Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpointfleetdm fleet
CVE-2026-34389Fleet's user account creation via invite does not enforce invited email addressfleetdm fleet
CVE-2026-34388Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpointfleetdm fleet
CVE-2026-34387Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scriptsfleetdm fleet
CVE-2026-34386Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global adminfleetdm fleet
CVE-2026-34385Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the databasefleetdm fleet
CVE-2026-29180Fleet's team maintainer can transfer hosts from any team via missing source team authorizationfleetdm fleet
CVE-2026-27806Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbitfleetdm fleet
CVE-2026-27465Fleet: Sensitive Google Calendar credentials disclosed to low-privileged usersfleetdm fleet
CVE-2026-26062Fleet server may terminate unexpectedly when handling certain gRPC requestsfleetdm fleet
CVE-2026-26060Fleet: Password reset tokens remain valid after password change for 24 hoursfleetdm fleet
CVE-2026-25963Fleet: Authorization Bypass in certificate template batch deletion for team administratorsfleetdm fleet
CVE-2026-24004Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpointfleetdm fleet
CVE-2026-23518Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollmentfleetdm fleet
CVE-2025-27509SAML authentication vulnerability due to improper SAML response validationfleetdm fleet
CVE-2022-23600Limited ability to spoof SAML authentication with missing audience verificationfleetdm fleet
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.