User Invitation Flow Issue in Fleet Device Management Software by FleetDM
CVE-2026-34389
4.9MEDIUM
What is CVE-2026-34389?
Fleet, the open-source device management software, has a vulnerability in its user invitation flow that allows an attacker with a valid invitation token to create an account using an arbitrary email address. This exploitation could grant the attacker the same user role as the original invite, including potentially privileged roles like global admin. This issue affects all versions prior to 4.81.0, which includes a fix to validate the email addresses against the invites.
Affected Version(s)
fleet < 4.81.0
