MEDIUM 5.3 NVD
CVE-2026-103265
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
References
- https://github.com/fleetdm/fleet/security/advisories/GHSA-97fg-h5wh-2399
- https://www.vulncheck.com/advisories/fleet-before-4.89.0-information-disclosure-via-mdm-co
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.