Vulnerabilidades en fleetdm
37 resultadosAnálisis Vexday
Fleet Device Management acumula 29 vulnerabilidades catalogadas, com 3 críticas (CVSS), mas nenhuma sob exploração ativa conhecida no momento. A fraqueza dominante é autenticação insuficiente (CWE-290), padrão recorrente que requer atenção na arquitetura; dos últimos 90 dias, 6 novas CVEs foram publicadas, sinalizando ritmo de descoberta consistente que demanda acompanhamento regular das correções.
CVE-2026-46370MEDIUMFleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpointEPSS 0.4%CVE-2026-46371MEDIUMFleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpointEPSS 0.4%CVE-2026-25963LOWFleet: Authorization Bypass in certificate template batch deletion for team administratorsEPSS 0.3%CVE-2026-41262MEDIUMFleet: Cross-Team Policy Data Exposure via Global Policy Read EndpointEPSS 0.3%CVE-2026-34389MEDIUMFleet's user account creation via invite does not enforce invited email addressEPSS 0.3%CVE-2026-23517MEDIUMFleet has an Access Control vulnerability in debug/pprof endpointsEPSS 0.3%CVE-2026-24004LOWFleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpointEPSS 0.3%CVE-2026-34391MEDIUMFleet Vulnerable to Windows MDM cross-device command disclosureEPSS 0.3%CVE-2026-23518CRITICALFleet has a JWT signature bypass vulnerability in Azure AD MDM enrollmentEPSS 0.3%CVE-2026-34385MEDIUMFleet's Apple MDM profile delivery has second-order SQL injection that can compromise the databaseEPSS 0.3%CVE-2026-22808MEDIUMFleet Windows MDM endpoint has a Cross-site Scripting vulnerabilityEPSS 0.3%CVE-2026-23998HIGHFleet has a Windows MDM management endpoint authentication bypassEPSS 0.2%CVE-2026-23999LOWFleet: Device lock PIN can be predicted if lock time is knownEPSS 0.1%CVE-2026-27806HIGHFleet Affected by Local Privilege Escalation via Tcl Command Injection in OrbitEPSS 0.1%CVE-2026-101047MEDIUMFleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLsEPSS —CVE-2026-101045HIGHFleet Homebrew Cask OS Command Injection via MetadataEPSS —CVE-2026-101046LOWFleet before 4.89.0 SQL Injection via ORDER BY Activity EndpointsEPSS —