CVE-2026-103265: Fleetdm Fleet

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.

Affected products

  • Fleetdm Fleet: before 4.89.0 (fixed in 4.89.0)

Published 2026-10-01. Last modified 2026-10-08.