Privilege Escalation Vulnerability in Fleet Device Management Platform by FleetDM
CVE-2026-46370

6.5MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-46370?

Fleet, an open-source device management platform that utilizes osquery, has a security vulnerability affecting versions up to and including 4.84.1. The host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) fails to properly validate user-supplied parameters. This oversight allows authenticated users with the minimal Observer role to exploit the order_key parameter to extract sensitive host enrollment secrets. By manipulating the sort order via this endpoint, attackers with Global or Team Observer access could conduct a binary search on sensitive fields such as h.node_key, revealing these long-lived shared secrets. The implications of this vulnerability are severe, as compromised secrets enable attackers to impersonate enrolled hosts, submit false query results, and interfere with compliance and policy enforcement. The issue has been remedied in version 4.84.2.

Affected Version(s)

fleet < 4.84.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.