{"apiVersion":"1.0","identifier":"CVE-2026-46371","description":"Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined database tables, including host enrollment secrets and Apple Push Notification Service tokens, through a sort-order oracle. The endpoint accepted a user-supplied order_key parameter that was not validated against a column allowlist, and because the underlying query joins the hosts and nano_enrollments tables, an attacker could set the sort column to a sensitive field and combine it with the cursor-based after parameter to binary-search the value one character at a time, with the presence or absence of results revealing each character even though the value never appeared in the response. With extracted node_key or orbit_node_key values an attacker could impersonate enrolled hosts to Fleet-s osquery and Orbit endpoints, submit fabricated host data, and retrieve pending scripts and commands. This issue is fixed in version 4.84.2.","publishedAt":"2026-08-26T20:17:23","lastModifiedAt":"2026-08-27T17:18:26","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-46371","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00219,"riskScore":0.66,"affectedProduct":"Fleet","affectedVersions":"<=4.84.1","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-46371","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-46371","en":"https://www.redsauce.net/en/cves/CVE-2026-46371","fr":"https://www.redsauce.net/fr/cves/CVE-2026-46371","pt":"https://www.redsauce.net/pt/cves/CVE-2026-46371","de":"https://www.redsauce.net/de/cves/CVE-2026-46371","sk":"https://www.redsauce.net/sk/cves/CVE-2026-46371","el":"https://www.redsauce.net/el/cves/CVE-2026-46371"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-46371"}}