Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses. | |
| Title | Fleet before 4.89.0 Information Disclosure via MDM Command Results | |
| First Time appeared |
Fleetdm
Fleetdm fleet |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fleetdm
Fleetdm fleet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T15:01:03.061Z
Reserved: 2026-09-30T10:58:33.573Z
Link: CVE-2026-103265
No data.
Status : Awaiting Analysis
Published: 2026-10-01T11:17:21.577
Modified: 2026-10-01T15:17:26.717
Link: CVE-2026-103265
No data.
OpenCVE Enrichment
Updated: 2026-10-01T14:15:09Z
Weaknesses