Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Fleet — Vulnerabilities & Security Advisories 36

All 36 CVE vulnerabilities found in Fleet, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with the Fleet product by Elastic. It compiles known security vulnerabilities, ranging from critical remote code execution flaws to lower-severity information disclosure issues, covering all publicly documented incidents from the product's inception through the present day. Users can track Elastic’s security advisory history to understand the timeline of patch releases and identify patterns in defect discovery. The page also allows for a deeper understanding of specific weakness classes by showing how often certain CWEs appear within this software ecosystem, helping security teams prioritize remediation efforts based on historical data. Additionally, users can look up the complete vulnerability history of Fleet to assess long-term security posture and compliance risks without needing to manually cross-reference multiple advisory sources. By centralizing this data, the page provides a comprehensive view of the product’s security landscape, enabling organizations to make informed decisions about deployment and risk management. The information presented is derived from official vendor disclosures, third-party security research, and automated scanning results where applicable, ensuring a broad and accurate representation of known threats. This resource serves as a single point of reference for security analysts, developers, and operations teams managing Fleet deployments who need to quickly evaluate the current risk profile and understand the context of past security incidents affecting the software.

Vendor: Fleet

CVE ID Title CVSS Severity Published
CVE-2026-75036 Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing CWE-918 5.3 Medium 2026-09-03
CVE-2026-54245 Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database CWE-89 7.6 High 2026-08-26
CVE-2026-46371 Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint CWE-89 6.5 Medium 2026-08-26
CVE-2026-46370 Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint CWE-89 6.5 Medium 2026-08-26
CVE-2026-41262 Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint CWE-863 4.3 Medium 2026-08-26
CVE-2026-48786 Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint CWE-200 6.5 Medium 2026-08-26
CVE-2026-46356 Fleet: IP spoofing allows bypassing API rate limiting CWE-290 - - 2026-05-14
CVE-2026-26191 Fleet vulnerable to OS command injection in software packages CWE-78 - - 2026-05-14
CVE-2026-26062 Fleet server may terminate unexpectedly when handling certain gRPC requests CWE-20 - - 2026-05-14
CVE-2026-24899 Fleet Windows MDM Azure AD JWT Authentication Bypass CWE-290 - - 2026-05-14
CVE-2026-24000 Fleet has a rate limiting bypass via untrusted client IP headers CWE-290 - - 2026-05-14
CVE-2026-23998 Fleet has a Windows MDM management endpoint authentication bypass CWE-295 - - 2026-05-14
CVE-2026-27806 Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit CWE-78 7.8 High 2026-04-08
CVE-2026-34391 Fleet Vulnerable to Windows MDM cross-device command disclosure CWE-488 6.5 - 2026-03-27
CVE-2026-34389 Fleet's user account creation via invite does not enforce invited email address CWE-287 8.8 - 2026-03-27
CVE-2026-34388 Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint CWE-703 6.5 - 2026-03-27
CVE-2026-34387 Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts CWE-78 7.2 - 2026-03-27
CVE-2026-34386 Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin CWE-89 6.5 - 2026-03-27
CVE-2026-34385 Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database CWE-89 8.8 - 2026-03-27
CVE-2026-29180 Fleet's team maintainer can transfer hosts from any team via missing source team authorization CWE-862 9.1 - 2026-03-27
CVE-2026-26061 Fleet's unbounded request body read allows remote Denial of Service CWE-770 7.5 - 2026-03-27
CVE-2026-26060 Fleet: Password reset tokens remain valid after password change for 24 hours CWE-613 7.5 - 2026-03-27
CVE-2026-27465 Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users CWE-201 4.3AI Medium AI 2026-02-26
CVE-2026-25963 Fleet: Authorization Bypass in certificate template batch deletion for team administrators CWE-863 3.8AI Low AI 2026-02-26
CVE-2026-23999 Fleet: Device lock PIN can be predicted if lock time is known CWE-330 5.7AI Medium AI 2026-02-26
CVE-2026-24004 Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint CWE-862 8.2AI High AI 2026-02-26
CVE-2026-26186 Fleet has a SQL injection via backtick escape in ORDER BY parameter CWE-89 8.1AI High AI 2026-02-26
CVE-2026-23518 Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment CWE-347 9.4AI Critical AI 2026-01-21
CVE-2026-23517 Fleet has an Access Control vulnerability in debug/pprof endpoints CWE-862 6.5AI Medium AI 2026-01-21
CVE-2026-22808 Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability CWE-79 8.8AI High AI 2026-01-21

All 36 known CVE vulnerabilities affecting Fleet with full Chinese analysis, references, and POCs where available.