SQL Injection Vulnerability in Fleet by FleetDM
CVE-2026-101046
2.3LOW
What is CVE-2026-101046?
An SQL injection vulnerability exists in Fleet versions before 4.89.0, specifically within the activity list endpoints. An authenticated user with read access can exploit this flaw to manipulate the ORDER BY clause, potentially inferring sensitive information from the results. Although there is no write access or privilege escalation, the vulnerability allows unauthorized inference of data from the activity_past table. The issue has been addressed in version 4.89.0, where the deprecated pagination helper was removed, and column sanitization improved.
Affected Version(s)
fleet 0 < 4.89.0
fleet 4.89.0
