PT-2026-28626 · Fleet · Fleet

Prateek-0490

·

Publicado

2026-03-27

·

Atualizado

2026-04-07

·

CVE-2026-34385

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.0
Description Fleet is open source device management software susceptible to a second-order SQL injection in its Apple MDM profile delivery pipeline. An attacker possessing a valid MDM enrollment certificate could potentially exfiltrate or modify the Fleet database contents. This includes sensitive information such as user credentials, API tokens, and device enrollment secrets.
Recommendations Update to version 4.81.0 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34385
GHSA-V895-833R-8C45
GO-2026-4914
SUSE-SU-2026:1205-1

Produtos afetados

Fleet