PT-2026-28628 · Jetbrains · Fleet

Prateek-0490

·

Published

2026-03-27

·

Updated

2026-05-14

·

CVE-2026-34387

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.1
Description Fleet is open source device management software susceptible to a command injection issue within its software installer pipeline. This allows an attacker to execute arbitrary code as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a specifically crafted software package. The issue resides in the uninstall scripts processing crafted software package metadata.
Recommendations Update to version 4.81.1 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-34387
GHSA-7RHW-5MPV-GP4H

Affected Products

Fleet