Fleet is an open-source device management and osquery endpoint visibility platform that, despite a narrow product portfolio, occupies a prominent position in the endpoint security and compliance tooling landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and concentrate in the core Fleet product across a recurring pattern of authentication, authorization, and command-execution weakness classes including authentication bypass, OS command injection, SQL injection, and improper access control. These flaws reflect the inherent complexity of a centralized management system that handles credentials, orchestrates queries across heterogeneous endpoints, and exposes administrative interfaces. Defenders should treat Fleet instances as high-value targets requiring strong network isolation and prompt patching, as the platform's role in security instrumentation amplifies the impact of access-control failures. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fleetdm over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26191CRITICAL Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute a | May 14, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-34387CRITICAL Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary c | Mar 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-23518CRITICAL Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow | Jan 21, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-26060HIGH Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain | Mar 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-23998HIGH Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without pr | May 14, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-34386HIGH Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Tea | Mar 27, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-29180HIGH Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from | Mar 27, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-26186HIGH Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the ` | Feb 26, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-27806HIGH Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog | Apr 8, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-46356HIGH Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limitin | May 14, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fleetdm.
Media articles that mention a CVE ID that affects a product developed by Fleetdm — matched by CVE ID, not by vendor name.