Second-Order SQL Injection Vulnerability in Fleet Device Management Software
CVE-2026-34385

6.2MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-34385?

Fleet, an open-source device management solution, has a vulnerability in its Apple MDM profile delivery pipeline that allows for second-order SQL injection. An attacker with valid MDM enrollment credentials could exploit this vulnerability to gain unauthorized access, modify, or exfiltrate sensitive data from the Fleet database, including user credentials, API tokens, and device enrollment secrets. This threat, detected in versions prior to 4.81.0, has been addressed in the latest update.

Affected Version(s)

fleet < 4.81.0

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.