PT-2026-28631 · Fleet · Fleet

Fuzzztf

·

Published

2026-03-27

·

Updated

2026-03-28

·

CVE-2026-34391

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.1
Description Fleet, an open source device management software, contains an issue in its Windows MDM command processing. A malicious enrolled device can access MDM commands intended for other devices. This could expose sensitive configuration data, including WiFi credentials, VPN secrets, and certificate payloads, across the entire Windows fleet.
Recommendations Update to version 4.81.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-34391
GHSA-WG7J-PCC3-H4RH

Affected Products

Fleet