VulnSea

github.com/fleetdm/fleet/v4 vulnerabilities

CVEs whose affected-version data names the github.com/fleetdm/fleet/v4 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-48786Medium· 6.5
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.25%via NVD
CVE-2026-46370Medium· 6.5
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.27%via NVD
CVE-2026-46371Medium· 6.5
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.22%via NVD
CVE-2026-41262Medium· 4.3
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowi…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.18%via NVD
GO-2026-6269None
4w ago

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GO-2026-6268None
4w ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GHSA-q9c5-pp7m-fm2gMedium· 5.3
1mo ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
GHSA-rxhg-vcww-2mpwLow· 3.1
1mo ago

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
github.com/fleetdm/fleet/v4 vulnerabilities (CVEs) · VulnSea