HIGH GitHub
CVE-2026-54245
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
### Summary
A SQL injection vulnerability in Fleet's Okta conditional access integration could allow an attacker who controls a single enrolled host to read or modify arbitrary data in the Fleet database, including stored session tokens. Disclosed session tokens may be replayed to act as a global administrator, which on a managed fleet leads to remote code execution on enrolled hosts.
### Impact
When Fleet Premium with Okta conditional access is configured, an unauthenticated request path tha
Affected Products
- go/github.com/fleetdm/fleet < 4.86.2
References
- https://github.com/advisories/GHSA-7q96-f8xw-jv5j
- https://github.com/fleetdm/fleet/security/advisories/GHSA-7q96-f8xw-jv5j
- https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.2
- https://github.com/advisories/GHSA-7q96-f8xw-jv5j
This high severity vulnerability was published on 2026-08-20 via GitHub. Affected: go/github.com/fleetdm/fleet < 4.86.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.