Information Disclosure in Fleet Product by FleetDM
CVE-2026-103265
5.3MEDIUM
What is CVE-2026-103265?
Versions of Fleet prior to 4.89.0 exhibit a security flaw where MDM command results are inadequately filtered by team authorization in the commands/results endpoint. This vulnerability allows team-scoped users to access MDM command results from hosts that belong to other teams when a shared command UUID is employed to target hosts across different teams. Consequently, sensitive information such as host UUIDs, command payloads, and device responses may be exposed to unauthorized users, posing a significant risk to data confidentiality.
Affected Version(s)
fleet 0 < 4.89.0
fleet 4.89.0
