Second-Order SQL Injection Vulnerability in Fleet Device Management Software
CVE-2026-34385
6.2MEDIUM
What is CVE-2026-34385?
Fleet, an open-source device management solution, has a vulnerability in its Apple MDM profile delivery pipeline that allows for second-order SQL injection. An attacker with valid MDM enrollment credentials could exploit this vulnerability to gain unauthorized access, modify, or exfiltrate sensitive data from the Fleet database, including user credentials, API tokens, and device enrollment secrets. This threat, detected in versions prior to 4.81.0, has been addressed in the latest update.
Affected Version(s)
fleet < 4.81.0
