GO-2026-6268None▾ SunlitFleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
github.com/fleetdm/fleet/v4 < 4.87.0Upgrade to a patched release:
github.com/fleetdm/fleet/v4 4.87.0Connected by shared product, vendor, weakness, or advisory.
GHSA-q9c5-pp7m-fm2gMedium· 5.3Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
CVE-2026-48786Medium· 6.5Fleet is an open-source device management platform built on osquery
GO-2026-6269NoneFleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
GHSA-rxhg-vcww-2mpwLow· 3.1Fleet: ORDER BY column injection on activity list endpoints
CVE-2026-46370Medium· 6.5Fleet is an open-source device management platform built on osquery
CVE-2026-46371Medium· 6.5Fleet is an open-source device management platform built on osquery