Team Isolation Bypass in Fleet Device Management by FleetDM
CVE-2026-41262
4.3MEDIUM
What is CVE-2026-41262?
The Fleet device management platform, built on osquery, has a significant vulnerability that allows authenticated users with observer-level access to bypass team isolation. In versions prior to 4.85.0, the global policy read endpoint fails to verify team ownership, allowing users to read policies from any other team. This occurs because the authorization for policy access is based on an unverified policy object. Attackers can exploit this oversight to enumerate sequential policy IDs, exposing sensitive policy SQL queries and compliance details across team boundaries. This vulnerability poses a risk to the confidentiality of security-monitoring strategies within organizations.
Affected Version(s)
fleet < 4.85.0
