Launch Week Day 1: Announcing Security Design Review
go

github.com/fleetdm/fleet/v4

View on go registry
43 Total advisories
43 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 6.5
Go

CVE-2026-46371

Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint

MEDIUM 6.5
Go

CVE-2026-46370

Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint

HIGH 7.5
Go

CVE-2026-23998

Fleet has a Windows MDM management endpoint authentication bypass

HIGH 7.5
Go

CVE-2026-24899

Fleet Windows MDM Azure AD JWT Authentication Bypass

UNKNOWN
Go

CVE-2026-23998

Windows MDM management endpoint authentication bypass in github.com/fleetdm/fleet/v4

UNKNOWN
Go

CVE-2026-26062

Fleet server may terminate unexpectedly when handling certain gRPC requests

MEDIUM 5.3
Go

CVE-2026-24000

Fleet has a rate limiting bypass via untrusted client IP headers

UNKNOWN
Go

CVE-2026-46356

Fleet: IP spoofing allows bypassing API rate limiting

UNKNOWN
Go

CVE-2026-26191

Fleet vulnerable to OS command injection in software packages

HIGH 7.8
Go

CVE-2026-27806

Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit

UNKNOWN
Go

CVE-2026-34388

Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint

UNKNOWN
Go

CVE-2026-34389

Fleet's user account creation via invite does not enforce invited email address

UNKNOWN
Go

CVE-2026-29180

A Fleet team maintainer can transfer hosts from any team via missing source team authorization

UNKNOWN
Go

CVE-2026-26061

Fleet's unbounded request body read allows remote Denial of Service

UNKNOWN
Go

CVE-2026-34385

Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the database

UNKNOWN
Go

CVE-2026-26060

Fleet: Password reset tokens remain valid after password change for 24 hours

UNKNOWN
Go

CVE-2026-34386

Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global admin

UNKNOWN
Go

CVE-2026-34388

Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-26061

Fleet's unbounded request body read allows remote Denial of Service in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-34386

Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global admin in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-34389

Fleet's user account creation via invite does not enforce invited email address in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-29180

A Fleet team maintainer can transfer hosts from any team via missing source team authorization in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-26060

Fleet: Password reset tokens remain valid after password change for 24 hours in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-34385

Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the database in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2020-26276

SAML authentication vulnerability due to stdlib XML parsing

UNKNOWN
Go

CVE-2026-25963

Fleet: Authorization Bypass in certificate template batch deletion for team administrators in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-25963

Fleet: Authorization Bypass in certificate template batch deletion for team administrators

UNKNOWN
Go

CVE-2026-27465

Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-27465

Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users

UNKNOWN
Go

CVE-2026-24004

Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-24004

Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint

UNKNOWN
Go

CVE-2026-23999

Fleet: Device lock PIN can be predicted if lock time is known in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-23999

Fleet: Device lock PIN can be predicted if lock time is known

UNKNOWN
Go

CVE-2026-26186

Fleet has an SQL Injection vulnerability via backtick escape in ORDER BY parameter in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-26186

Fleet has an SQL Injection vulnerability via backtick escape in ORDER BY parameter

UNKNOWN
Go

CVE-2026-23517

Fleet has an Access Control vulnerability in debug/pprof endpoints

UNKNOWN
Go

CVE-2026-23518

Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-22808

Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2026-22808

Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

UNKNOWN
Go

CVE-2026-23517

Fleet has an Access Control vulnerability in debug/pprof endpoints in github.com/fleetdm/fleet

UNKNOWN
Go

CVE-2025-27509

Fleet has SAML authentication vulnerability due to improper SAML response validation

UNKNOWN
Go

CVE-2025-27509

Fleet has SAML authentication vulnerability due to improper SAML response validation in github.com/fleetdm/fleet

MEDIUM 5.3
Go

CVE-2022-23600

Limited ability to spoof SAML authentication with missing audience verification in Fleet

Ready to move

Start Securing

Free, no credit card | First findings in minutes