Impact
A classic SQL injection flaw exists in Fleet’s Okta conditional access endpoint. The endpoint incorporates a value supplied by a host’s agent directly into a database query without proper parameterization. An attacker who gains control over any single enrolled host can inject malicious SQL through the agent, allowing the attacker to read or modify arbitrary rows in the Fleet database, including session tokens. With stolen tokens the attacker can assume a global administrator role and execute privileged scripts on managed hosts, effectively achieving remote code execution across the fleet.
Affected Systems
The vulnerability affects the fleetdm:fleet product, specifically installations that use Fleet Premium with the Okta conditional access integration enabled. Versions earlier than 4.86.2 are vulnerable; the issue was fixed in release 4.86.2 and later.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity level, while the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. The attack path is relatively low‑barrier because an attacker only needs control of a single host, which is the lowest privilege position in the product. Once a host is compromised, the attacker can extract credentials, elevate to administrative privileges, and gain full control of the entire fleet, resulting in a high overall risk.
OpenCVE Enrichment
Github GHSA