PT-2026-28346 · Fleet · Fleet
Fuzzztf
·
Publicado
2026-03-27
·
Atualizado
2026-04-07
·
CVE-2026-26060
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fleet versions prior to 4.81.0
Description
Fleet’s password management logic had a flaw that allowed previously issued password reset tokens to remain valid even after a user changed their password. This meant a stale token could be reused to reset the account password after a defensive password change. Exploitation requires prior compromise of a password reset token and is limited by the token’s 24-hour expiration period. The issue does not allow discovery of reset tokens, does not bypass authentication on its own, and does not affect accounts without an existing valid reset token.
Recommendations
Versions prior to 4.81.0 should be updated to version 4.81.0 or later. As a temporary workaround, users who believe a password reset token may have been exposed should wait for the token to expire before reusing the account, or contact a Fleet administrator to invalidate active sessions.
Exploit
Correção
Insufficient Session Expiration
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fleet