fleetdm has 10 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 9. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-89 (4) and CWE-200 (3). Most affected products: github.com/fleetdm/fleet/v4 (8), fleet (1), github.com/fleetdm/fleet (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 9 prev 1
Products
- github.com/fleetdm/fleet/v4 8
- fleet 1
- github.com/fleetdm/fleet 1
Worst active — by depth score
CVE-2026-27806High· 7.8Fleet is open source device management software43CVE-2026-54245HighFleet is an open-source device management platform built on osquery41CVE-2026-48786Medium· 6.5Fleet is an open-source device management platform built on osquery36CVE-2026-46371Medium· 6.5Fleet is an open-source device management platform built on osquery36CVE-2026-46370Medium· 6.5Fleet is an open-source device management platform built on osquery36
fleetdm vulnerabilities
CVEs affecting fleetdm, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-54245HighFleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a dat…
CVE-2026-48786Medium· 6.5Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…
CVE-2026-46370Medium· 6.5Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…
CVE-2026-46371Medium· 6.5Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…
CVE-2026-41262Medium· 4.3Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowi…
GO-2026-6269NoneFleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
GO-2026-6268NoneFleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
GHSA-q9c5-pp7m-fm2gMedium· 5.3Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
GHSA-rxhg-vcww-2mpwLow· 3.1Fleet: ORDER BY column injection on activity list endpoints
Fleet: ORDER BY column injection on activity list endpoints
CVE-2026-27806High· 7.8Fleet is open source device management software
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script ex…