Impact
This vulnerability occurs in Fleet versions prior to 4.89.0 where the MDM command results endpoint fails to filter results by team authorization. Consequently, a user with team‑scoped access can retrieve MDM command results belonging to hosts on other teams when a shared command UUID is used to target hosts across multiple teams. This exposes sensitive information such as host UUIDs, the original command payload, and device responses, thereby compromising confidentiality.
Affected Systems
The affected product is Fleet by FleetDM. All releases prior to version 4.89.0 are impacted. The vulnerability specifically involves the commands/results endpoint of the Fleet API.
Risk and Exploitability
The CVSS score for this issue is 5.3, indicating moderate severity. EPSS is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be able to authenticate as a team‑scoped user and invoke the commands/results API with a shared command UUID that spans multiple teams. Once, they can read command results from hosts that belong to other teams. No exploitation technique beyond authorized API usage is described in the advisory, suggesting that exploiting this flaw does not require elevated privilege beyond normal team access.
OpenCVE Enrichment