VendorsFleetdmfleetall versions
Vulnerabilities

Fleetdm Fleet Device Management Fleet

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2020-26276
SAML authentication vulnerability in Fleet
Published 2020-12-17 · Modified
10.0EPSS 0.022
CVE-2026-34387
Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts
Published 2026-03-27 · Analyzed
9.8EPSS 0.013
CVE-2026-26191
Fleet vulnerable to OS command injection in software packages
Published 2026-05-14 · Analyzed
9.8EPSS 0.008
CVE-2026-23518
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Published 2026-01-21 · Analyzed
9.8EPSS 0.003
CVE-2026-26060
Fleet: Password reset tokens remain valid after password change for 24 hours
Published 2026-03-27 · Analyzed
8.8EPSS 0.003
CVE-2026-34386
Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin
Published 2026-03-27 · Analyzed
8.8EPSS 0.003
CVE-2026-29180
Fleet's team maintainer can transfer hosts from any team via missing source team authorization
Published 2026-03-27 · Analyzed
8.8EPSS 0.003
CVE-2026-26186
Fleet has a SQL injection via backtick escape in ORDER BY parameter
Published 2026-02-26 · Analyzed
8.8EPSS 0.003
CVE-2026-26061
Fleet's unbounded request body read allows remote Denial of Service
Published 2026-03-27 · Analyzed
8.7EPSS 0.004
CVE-2026-26062
Fleet server may terminate unexpectedly when handling certain gRPC requests
Published 2026-05-14 · Analyzed
8.7EPSS 0.004
CVE-2026-24899
Fleet Windows MDM Azure AD JWT Authentication Bypass
Published 2026-05-14 · Analyzed
8.2EPSS 0.004
CVE-2026-23998
Fleet has a Windows MDM management endpoint authentication bypass
Published 2026-05-14 · Analyzed
8.2EPSS 0.002
CVE-2022-24841
Improper Authorization in github.com/fleetdm/fleet
Published 2022-04-18 · Modified
8.1EPSS 0.008
CVE-2026-23517
Fleet has an Access Control vulnerability in debug/pprof endpoints
Published 2026-01-21 · Analyzed
8.1EPSS 0.003
CVE-2026-34385
Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database
Published 2026-03-27 · Analyzed
8.1EPSS 0.002
CVE-2026-27806
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit
Published 2026-04-08 · Analyzed
7.8EPSS 0.001
CVE-2026-46356
Fleet: IP spoofing allows bypassing API rate limiting
Published 2026-05-14 · Analyzed
7.5EPSS 0.003
CVE-2026-34388
Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint
Published 2026-03-27 · Analyzed
7.5EPSS 0.003
CVE-2026-34391
Fleet Vulnerable to Windows MDM cross-device command disclosure
Published 2026-03-27 · Analyzed
7.5EPSS 0.002
CVE-2026-24000
Fleet has a rate limiting bypass via untrusted client IP headers
Published 2026-05-14 · Analyzed
6.9EPSS 0.004
CVE-2022-23600
Limited ability to spoof SAML authentication with missing audience verification
Published 2022-02-04 · Modified
6.5EPSS 0.009
CVE-2026-27465
Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users
Published 2026-02-26 · Analyzed
6.5EPSS 0.002
CVE-2026-25963
Fleet: Authorization Bypass in certificate template batch deletion for team administrators
Published 2026-02-26 · Analyzed
6.5EPSS 0.002
CVE-2026-34389
Fleet's user account creation via invite does not enforce invited email address
Published 2026-03-27 · Analyzed
6.5EPSS 0.002
CVE-2026-22808
Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability
Published 2026-01-21 · Analyzed
5.5EPSS 0.003
CVE-2026-23999
Fleet: Device lock PIN can be predicted if lock time is known
Published 2026-02-26 · Analyzed
5.5EPSS 0.001
CVE-2026-24004
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint
Published 2026-02-26 · Analyzed
5.3EPSS 0.003
CVE-2021-21296
Denial-of-service in Fleet
Published 2021-02-10 · Modified
4.0EPSS 0.019