User Invitation Flow Issue in Fleet Device Management Software by FleetDM
CVE-2026-34389

4.9MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-34389?

Fleet, the open-source device management software, has a vulnerability in its user invitation flow that allows an attacker with a valid invitation token to create an account using an arbitrary email address. This exploitation could grant the attacker the same user role as the original invite, including potentially privileged roles like global admin. This issue affects all versions prior to 4.81.0, which includes a fix to validate the email addresses against the invites.

Affected Version(s)

fleet < 4.81.0

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.