Description
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

This vulnerability occurs in Fleet versions prior to 4.89.0 where the MDM command results endpoint fails to filter results by team authorization. Consequently, a user with team‑scoped access can retrieve MDM command results belonging to hosts on other teams when a shared command UUID is used to target hosts across multiple teams. This exposes sensitive information such as host UUIDs, the original command payload, and device responses, thereby compromising confidentiality.

Affected Systems

The affected product is Fleet by FleetDM. All releases prior to version 4.89.0 are impacted. The vulnerability specifically involves the commands/results endpoint of the Fleet API.

Risk and Exploitability

The CVSS score for this issue is 5.3, indicating moderate severity. EPSS is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be able to authenticate as a team‑scoped user and invoke the commands/results API with a shared command UUID that spans multiple teams. Once, they can read command results from hosts that belong to other teams. No exploitation technique beyond authorized API usage is described in the advisory, suggesting that exploiting this flaw does not require elevated privilege beyond normal team access.

Generated by OpenCVE AI on October 1, 2026 at 14:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Fleet to version 4.89.0 or later to address the command result filtering bug.
  • Revoke or regenerate any shared MDM command UUIDs that could target hosts across multiple teams to prevent further exposure.
  • Verify that team‑scoped users can only query the commands/results endpoint for hosts within their own team and audit API usage logs for unauthorized access patterns.

Generated by OpenCVE AI on October 1, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
Title Fleet before 4.89.0 Information Disclosure via MDM Command Results
First Time appeared Fleetdm
Fleetdm fleet
Weaknesses CWE-863
CPEs cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*
Vendors & Products Fleetdm
Fleetdm fleet
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:01:03.061Z

Reserved: 2026-09-30T10:58:33.573Z

Link: CVE-2026-103265

cve-icon Vulnrichment

Updated: 2026-10-01T15:00:57.903Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T11:17:21.577

Modified: 2026-10-01T15:17:26.717

Link: CVE-2026-103265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses