CVE-2026-103265
Received Received - Intake

Fleet MDM Command Result Authorization Bypass

Vulnerability report for CVE-2026-103265, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fleetdm fleet to 4.89.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Fleet versions before 4.89.0 have an authorization flaw in the MDM command results endpoint. Team-scoped users can access MDM command results for hosts on other teams if a shared command UUID targets multiple teams. This exposes sensitive data like host UUIDs, command payloads, and device responses.

Detection Guidance

Check FleetDM server logs for unauthorized access to MDM command results across teams. Look for queries using shared command UUIDs that return data from multiple teams. Verify if team-scoped users can retrieve host UUIDs, command payloads, or device responses outside their assigned teams.

Impact Analysis

An attacker with team-scoped access could view sensitive information from other teams, including host identifiers and device responses. This could lead to unauthorized data exposure but does not allow issuing commands to other teams' hosts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating confidentiality requirements in GDPR and HIPAA. Exposure of host UUIDs and device responses may constitute a data breach under these regulations.

Mitigation Strategies

Upgrade FleetDM to version 4.89.0 or later immediately. Avoid issuing MDM commands targeting hosts across multiple teams until patched. Review existing command results for unauthorized access and restrict team-scoped user permissions to their respective teams.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103265. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart