← Πίσω στην αναζήτηση CVE

CVE-2026-46371

Fleet

Περιγραφή

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined database tables, including host enrollment secrets and Apple Push Notification Service tokens, through a sort-order oracle. The endpoint accepted a user-supplied order_key parameter that was not validated against a column allowlist, and because the underlying query joins the hosts and nano_enrollments tables, an attacker could set the sort column to a sensitive field and combine it with the cursor-based after parameter to binary-search the value one character at a time, with the presence or absence of results revealing each character even though the value never appeared in the response. With extracted node_key or orbit_node_key values an attacker could impersonate enrolled hosts to Fleet-s osquery and Orbit endpoints, submit fabricated host data, and retrieve pending scripts and commands. This issue is fixed in version 4.84.2.

CVSS 6.5EPSS 0.219%Κίνδυνος 0.66
Προβολή πηγής
Δημοσίευση
2026-08-26 20:17:23
Επηρεαζόμενες εκδόσεις
<=4.84.1
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-08-27 17:18:26
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N