OS Command Injection Vulnerability in Fleet Maintained MacOS Apps via Homebrew
CVE-2026-101045

8.9HIGH

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101045?

The vulnerability in Fleet's app installation scripts for macOS results from improper escaping of Homebrew cask metadata prior to August 19, 2026. An attacker can exploit this flaw to inject shell metacharacters into scripts that execute with root privileges on managed macOS systems. This security oversight allows arbitrary command execution when crafted metadata is submitted to an upstream Homebrew cask without the need for Fleet credentials. Despite the chance of pre-existing review processes, successful exploitation provides significant control over affected systems. A remediation was deployed on August 19, 2026, ensuring that subsequent manifests escape cask metadata appropriately and applies to all affected deployments without user intervention.

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.