VulnSea

fleetdm has 10 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 9. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-89 (4) and CWE-200 (3). Most affected products: github.com/fleetdm/fleet/v4 (8), fleet (1), github.com/fleetdm/fleet (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
9 prev 1

Products

  • github.com/fleetdm/fleet/v4 8
  • fleet 1
  • github.com/fleetdm/fleet 1
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

fleetdm vulnerabilities

CVEs affecting fleetdm, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-54245High
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a dat…

Twilightfleetdm · github.com/fleetdm/fleetEPSS 0.34%via NVD
CVE-2026-48786Medium· 6.5
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.25%via NVD
CVE-2026-46370Medium· 6.5
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.27%via NVD
CVE-2026-46371Medium· 6.5
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.22%via NVD
CVE-2026-41262Medium· 4.3
3w ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowi…

Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.18%via NVD
GO-2026-6269None
4w ago

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GO-2026-6268None
4w ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GHSA-q9c5-pp7m-fm2gMedium· 5.3
1mo ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
GHSA-rxhg-vcww-2mpwLow· 3.1
1mo ago

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
CVE-2026-27806High· 7.8
5mo ago

Fleet is open source device management software

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script ex…

Twilightfleetdm · fleetEPSS 0.11%via NVD
fleetdm vulnerabilities (CVEs) · VulnSea