Fleet 是一个基于 osquery 构建的开源设备管理平台。在 4.85.0 之前的版本中,全局策略读取端点(GET /api/latest/fleet/policies/{policy_id})未能验证所请求策略的团队归属,这使得任何仅拥有单个团队观察者(observer)级别权限的已认证用户,能够读取其他团队策略的完整详情,从而绕过 Fleet 的团队隔离模型。具体而言,处理程序使用一个 TeamID 为 nil 的空策略对象进行授权检查,而授权规则允许拥有任意团队角色的用户通过该检查;随后,系统按 ID
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54245 | 7.6 HIGH | Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise |
| CVE-2026-48786 | 6.5 MEDIUM | Fleet: Observer-class users can view team enroll secrets and credential-bearing configurat |
| CVE-2026-46370 | 6.5 MEDIUM | Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-l |
| CVE-2026-46371 | 6.5 MEDIUM | Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM comman |
No comments yet