PT-2026-22116 · Fleet · Fleet

Secfox-Ai

·

Published

2026-02-26

·

Updated

2026-03-25

·

CVE-2026-25963

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.80.1
Description Fleet’s certificate template deletion API had a broken authorization check. This allowed a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. The issue stemmed from a validation flaw in the batch deletion endpoint, where the system used a user-supplied team identifier without verifying if the certificate template IDs being deleted actually belonged to that team. This could disrupt certificate-based workflows, including device enrollment, Wi-Fi authentication, VPN access, and other certificate-dependent configurations. The impact is limited to the integrity and availability of certificate templates across teams.
Recommendations Upgrade to Fleet version 4.80.1 or later. Restrict access to certificate template management to trusted users. Avoid delegating team administrator permissions where not strictly required.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25963
GHSA-5JVP-M9H4-253H
GO-2026-4561
SUSE-SU-2026:1042-1

Affected Products

Fleet