VulnSea

Fleet vulnerabilities

CVEs whose affected-version data names the Fleet package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-93538High· 7.1
today

Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such…

▾ TwilightSUSE · Fleetvia CVEORG
CVE-2026-93539Medium· 5.4
today

Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the sp…

▾ SunlitSUSE · Fleetvia CVEORG
CVE-2026-93540Medium· 6.5
today

Fleet applies namespace labels and annotations without the bundle's service account privileges

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorizat…

▾ SunlitSUSE · Fleetvia CVEORG
CVE-2026-93537Medium· 6.5
today

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesyst…

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesyst…

▾ SunlitSUSE · Fleetvia NVD
CVE-2026-101047Medium· 5.3
yesterday

Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token

Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM c…

▾ Sunlitfleetdm · fleetvia NVD
CVE-2026-101045High· 8.0
yesterday

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them,…

▾ Twilightfleetdm · fleetvia NVD
CVE-2026-101046Low· 3.1
yesterday

Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities)

Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToS…

▾ Sunlitfleetdm · fleetvia NVD
CVE-2026-27806High· 7.8
5mo ago

Fleet is open source device management software

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script ex…

▾ Twilightfleetdm · fleetEPSS 0.11%via NVD
Fleet vulnerabilities (CVEs) · VulnSea