{"apiVersion":"1.0","identifier":"CVE-2026-48786","description":"Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-privilege observer-class users. Other team-facing endpoints mask these fields for observers, but the target search endpoint did not apply the same sanitization, so an authenticated user with the Observer, Observer+, or Technician role, whether global or team-scoped, could retrieve the secrets and agent options by performing a target search against an observer-runnable query. With a leaked team enroll secret an attacker could enroll unauthorized hosts into the affected team, and if the team-s agent options contained credentials such as AWS secret access keys or proxy passwords, those values were disclosed as well. This issue is fixed in version 4.87.0.","publishedAt":"2026-08-26T19:16:50","lastModifiedAt":"2026-08-26T20:17:52","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48786","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00251,"riskScore":0.66,"affectedProduct":"Fleet","affectedVersions":"<4.87.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-48786","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-48786","en":"https://www.redsauce.net/en/cves/CVE-2026-48786","fr":"https://www.redsauce.net/fr/cves/CVE-2026-48786","pt":"https://www.redsauce.net/pt/cves/CVE-2026-48786","de":"https://www.redsauce.net/de/cves/CVE-2026-48786","sk":"https://www.redsauce.net/sk/cves/CVE-2026-48786","el":"https://www.redsauce.net/el/cves/CVE-2026-48786"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-48786"}}