๐Ÿ” CVE Alert

CVE-2026-103265

MEDIUM 4.3

Fleet before 4.89.0 Information Disclosure via MDM Command Results

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.

CWE CWE-863
Vendor fleetdm
Product fleet
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for fleetdm fleet

Be the first to know when new medium vulnerabilities affecting fleetdm fleet are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

fleetdm / fleet
0 < 4.89.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fleetdm/fleet/security/advisories/GHSA-97fg-h5wh-2399 vulncheck.com: https://www.vulncheck.com/advisories/fleet-before-4.89.0-information-disclosure-via-mdm-command-results

Credits

๐Ÿ” geo-chen