Improper Exposure of Sensitive Information in Fleet Device Management Platform
CVE-2026-48786

6.5MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-48786?

The Fleet device management platform, built on osquery, contains a vulnerability that allows low-privileged users, such as Observer and Technician roles, to access sensitive information through its target search endpoint. Specifically, this endpoint exposes unmasked team enrollment secrets and configuration details, including credential-bearing agent options. Affected users could exploit this weakness to retrieve confidential data, potentially enrolling unauthorized hosts and gaining access to critical credentials. This security issue has been resolved in Fleet version 4.87.0.

Affected Version(s)

fleet < 4.87.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.