Sensitive Data Exposure in Fleet Device Management Platform by FleetDM
CVE-2026-46371
6.5MEDIUM
What is CVE-2026-46371?
An authentication flaw in the Fleet device management platform allows a user with minimal privileges to exploit the Apple MDM commands listing endpoint. By manipulating the order_key parameter, an attacker can circumvent validations, leading to the extraction of sensitive data such as host enrollment secrets and Apple Push Notification Service tokens. This vulnerability enables potential impersonation of enrolled hosts, allowing attackers to submit false data and access critical commands and scripts. The issue has been addressed in version 4.84.2.
Affected Version(s)
fleet < 4.84.2
