All 36 CVE vulnerabilities found in Fleet, with AI-generated Chinese analysis, references, and POCs.
This page aggregates Common Weakness Enumerations (CWE) associated with the Fleet product by Elastic. It compiles known security vulnerabilities, ranging from critical remote code execution flaws to lower-severity information disclosure issues, covering all publicly documented incidents from the product's inception through the present day. Users can track Elastic’s security advisory history to understand the timeline of patch releases and identify patterns in defect discovery. The page also allows for a deeper understanding of specific weakness classes by showing how often certain CWEs appear within this software ecosystem, helping security teams prioritize remediation efforts based on historical data. Additionally, users can look up the complete vulnerability history of Fleet to assess long-term security posture and compliance risks without needing to manually cross-reference multiple advisory sources. By centralizing this data, the page provides a comprehensive view of the product’s security landscape, enabling organizations to make informed decisions about deployment and risk management. The information presented is derived from official vendor disclosures, third-party security research, and automated scanning results where applicable, ensuring a broad and accurate representation of known threats. This resource serves as a single point of reference for security analysts, developers, and operations teams managing Fleet deployments who need to quickly evaluate the current risk profile and understand the context of past security incidents affecting the software.
Vendor: Fleet
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-27509 | SAML authentication vulnerability due to improper SAML response validation CWE-285 | 8.8 | - | 2025-03-06 |
| CVE-2022-24841 | Improper Authorization in github.com/fleetdm/fleet CWE-284 | 6.5 | Medium | 2022-04-18 |
| CVE-2022-23600 | Limited ability to spoof SAML authentication with missing audience verification CWE-287 | 5.3 | Medium | 2022-02-04 |
| CVE-2021-21296 | Denial-of-service in Fleet CWE-400 | 2.7 | Low | 2021-02-10 |
| CVE-2020-26276 | SAML authentication vulnerability in Fleet CWE-290 | 10.0 | Critical | 2020-12-17 |
| CVE-2019-1020009 | Fleet 信任管理问题漏洞 | 7.5 | - | 2019-07-29 |
All 36 known CVE vulnerabilities affecting Fleet with full Chinese analysis, references, and POCs where available.