THREAT OPS › Threat News › [GHSA] GHSA-88p2-jj8w-j8qg (medium) — Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
[GHSA] GHSA-88p2-jj8w-j8qg (medium) — Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
GHSA-88p2-jj8w-j8qg Severity: medium CVE: CVE-2026-48786
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
### Summary
The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-48786cve
- https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEwurl
- security@fleetdm.comemail
Original source: https://github.com/advisories/GHSA-88p2-jj8w-j8qg