CVE-2026-34391 PUBLISHED

Fleet Vulnerable to Windows MDM cross-device command disclosure

Assigner: GitHub_M
Reserved: 27.03.2026 Published: 27.03.2026 Updated: 27.03.2026

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet. Version 4.81.1 patches the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
CVSS Score: 6.6

Product Status

Vendor fleetdm
Product fleet
Versions
  • Version < 4.81.1 is affected

References

Problem Types

  • CWE-488: Exposure of Data Element to Wrong Session CWE