CVE-2026-34387 details a command injection vulnerability in Fleet device management software, affecting versions prior to 4.81.1. An attacker with high privileges could exploit this flaw by deploying a crafted software package and then triggering its uninstall, leading to arbitrary code execution as root or SYSTEM on managed hosts. Rated as MEDIUM severity (CVSS 5.7), the attack has low complexity but requires user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.81.1CPE matchmatch criteria | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.