Логотип exploitDog
bind:CVE-2026-22808
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22808

Количество 2

Количество 2

nvd логотип

CVE-2026-22808

19 дней назад

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorage. This could allow unauthorized access to Fleet, including administrative access, visibility into device data, and modification of configuration. Versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

EPSS: Низкий
github логотип

GHSA-gfpw-jgvr-cw4j

20 дней назад

Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22808

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorage. This could allow unauthorized access to Fleet, including administrative access, visibility into device data, and modification of configuration. Versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

0%
Низкий
19 дней назад
github логотип
GHSA-gfpw-jgvr-cw4j

Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

0%
Низкий
20 дней назад

Уязвимостей на страницу