CVE-2026-34386 is a high-severity SQL injection vulnerability affecting Fleet device management software versions prior to 4.81.0. An authenticated Team Admin or Global Admin can exploit this via direct API calls to modify arbitrary team configurations, exfiltrate sensitive database data, and inject arbitrary content, leading to a CVSS score of 8.8. Despite being on the CISA Hot List, there is currently no evidence of active exploitation, nor is public exploit code or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.81.0CPE matchmatch criteria | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.