SQL Injection Vulnerability in Fleet by FleetDM
CVE-2026-101046

2.3LOW

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101046?

An SQL injection vulnerability exists in Fleet versions before 4.89.0, specifically within the activity list endpoints. An authenticated user with read access can exploit this flaw to manipulate the ORDER BY clause, potentially inferring sensitive information from the results. Although there is no write access or privilege escalation, the vulnerability allows unauthorized inference of data from the activity_past table. The issue has been addressed in version 4.89.0, where the deprecated pagination helper was removed, and column sanitization improved.

Affected Version(s)

fleet 0 < 4.89.0

fleet 4.89.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

axel-corsiez
.