github.com/fleetdm/fleet
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/fleetdm/fleetpage 1 of 1
- CVE-2026-22808MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.75.22026-01-21
fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator…
- CVE-2026-23517HIGHCVSS 8.1EG 8.1✓ Fixed in 4.75.22026-01-21
Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a res…
- CVE-2026-23518CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.43.5-0.20260112202845-e225ef57912c2026-01-21
Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that ar…
Check whether github.com/fleetdm/fleet is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/fleetdm/fleet CVEs against the assets you own.
Start Free Scan →