github.com/fleetdm/fleet/v4
Go15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/fleetdm/fleet/v4page 1 of 1
- CVE-2020-26276CRITICALCVSS 10.0EG 10.0✓ Fixed in 3.5.12020-12-17
Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unv…
- CVE-2022-23600MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.9.12022-02-04
fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1…
- CVE-2025-27509CRITICALCVSS 9.3EG 0.02025-03-06
fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account …
- CVE-2026-23518CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.78.32026-01-21
Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that ar…
- CVE-2026-23998HIGHCVSS 7.5EG 7.5✓ Fixed in 4.81.02026-05-14
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstan…
- CVE-2026-24000MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.80.12026-05-14
Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoo…
- CVE-2026-24899HIGHCVSS 7.5EG 7.5✓ Fixed in 4.82.02026-05-14
Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures u…
- CVE-2026-26062MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.81.02026-05-14
Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input values were not handled g…
- CVE-2026-26191CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.81.12026-05-14
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows)…
- CVE-2026-27806HIGHCVSS 7.8EG 7.8✓ Fixed in 4.81.12026-04-08
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script exec…
- CVE-2026-34385HIGHCVSS 8.1EG 8.1✓ Fixed in 4.81.02026-03-27
Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or mo…
- CVE-2026-34386HIGHCVSS 8.8EG 8.8✓ Fixed in 4.81.02026-03-27
Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team…
- CVE-2026-34388HIGHCVSS 7.5EG 7.5✓ Fixed in 4.81.02026-03-27
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type v…
- CVE-2026-34389MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.81.02026-03-27
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with th…
- CVE-2026-46356HIGHCVSS 7.5EG 7.5✓ Fixed in 4.80.12026-05-14
Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force…
Check whether github.com/fleetdm/fleet/v4 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/fleetdm/fleet/v4 CVEs against the assets you own.
Start Free Scan →