Sensitive Data Exposure in Fleet Device Management Platform by FleetDM
CVE-2026-46371

6.5MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-46371?

An authentication flaw in the Fleet device management platform allows a user with minimal privileges to exploit the Apple MDM commands listing endpoint. By manipulating the order_key parameter, an attacker can circumvent validations, leading to the extraction of sensitive data such as host enrollment secrets and Apple Push Notification Service tokens. This vulnerability enables potential impersonation of enrolled hosts, allowing attackers to submit false data and access critical commands and scripts. The issue has been addressed in version 4.84.2.

Affected Version(s)

fleet < 4.84.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.