{"apiVersion":"1.0","identifier":"CVE-2026-41262","description":"Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authenticated user with observer-level access on any single team to read the full details of policies belonging to any other team and bypass Fleet-s team isolation model. The handler authorizes the request against an empty policy object whose TeamID is nil, which an authorization rule permits for any user holding a role on any team, and then fetches the policy by ID with no team filter and returns it without any post-fetch scope check. Because policy IDs are sequential integers, an attacker can enumerate them to read other teams- policy SQL queries, host pass and fail counts, and associated software-installer and script metadata, exposing security-monitoring strategies and compliance posture across team boundaries. This issue is fixed in version 4.85.0.","publishedAt":"2026-08-26T19:16:50","lastModifiedAt":"2026-08-26T20:17:21","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41262","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","epssProbability":0.00183,"riskScore":0.44,"affectedProduct":"Fleet","affectedVersions":"<4.85.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-41262","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-41262","en":"https://www.redsauce.net/en/cves/CVE-2026-41262","fr":"https://www.redsauce.net/fr/cves/CVE-2026-41262","pt":"https://www.redsauce.net/pt/cves/CVE-2026-41262","de":"https://www.redsauce.net/de/cves/CVE-2026-41262","sk":"https://www.redsauce.net/sk/cves/CVE-2026-41262","el":"https://www.redsauce.net/el/cves/CVE-2026-41262"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-41262"}}