CVE-2026-26060 is a high-severity vulnerability affecting Fleet, an open-source device management software, in versions prior to 4.81.0. This flaw allows previously issued password reset tokens to remain valid even after a user changes their password, enabling an attacker to reuse a stale token to reset an account. With a CVSS score of 8.8 (High), this vulnerability has a network attack vector and low attack complexity, potentially leading to high impacts on confidentiality, integrity, and availability of affected accounts. There is currently no evidence of active exploitation, nor are public exploit modules available. Community discussion is minimal, and the EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.81.0CPE matchmatch criteria | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.