← Zurück zur CVE-Suche

CVE-2026-48786

Fleet

Beschreibung

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-privilege observer-class users. Other team-facing endpoints mask these fields for observers, but the target search endpoint did not apply the same sanitization, so an authenticated user with the Observer, Observer+, or Technician role, whether global or team-scoped, could retrieve the secrets and agent options by performing a target search against an observer-runnable query. With a leaked team enroll secret an attacker could enroll unauthorized hosts into the affected team, and if the team-s agent options contained credentials such as AWS secret access keys or proxy passwords, those values were disclosed as well. This issue is fixed in version 4.87.0.

CVSS 6.5EPSS 0.251%Risiko 0.66
Quelle öffnen
Veröffentlicht
2026-08-26 19:16:50
Betroffene Versionen
<4.87.0
Typ
Webanwendung
Zuletzt geändert
2026-08-26 20:17:52
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N