CVE-2021-21296Low· 2.7▾ SunlitFleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.9%
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this vulnerability to be low given the requirement that the actor has a valid node key. There is no information disclosure, privilege escalation, or code execution. The issue is fixed in Fleet 3.7.0.
fleet < 3.7.0Upgrade past the affected range:
fleet 3.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103264Critical· 9.1Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs
CVE-2026-103265Medium· 4.3Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint
CVE-2026-88808High· 8.8A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment
CVE-2026-93538High· 7.1A cross-tenant authorization issue was discovered in SUSE Rancher Fleet
CVE-2026-93539Medium· 5.4A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service)
CVE-2026-93540Medium· 6.5A privilege mismatch was found in Fleet