CVE-2026-34386 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authent…
Medium CVSS: 6.3

CVE-2026-34386

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject arbitrary content into team configs via direct API calls. Version 4.81.0 patches the issue.
Vendor
Fleetdm
Product
Fleet
CWE
CWE-89
Yayın Tarihi
2026-03-27 19:16:43
Güncelleme
2026-04-02 17:04:41
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar