THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-46370 (MEDIUM 6.5) — Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment sec

[NVD] CVE-2026-46370 (MEDIUM 6.5) — Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment sec

mednvdPublished 2026-08-26

CVE-2026-46370 CVSS: 6.5 MEDIUM Published: 2026-08-26T20:17:23.327

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-order oracle. The endpoint accep

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-46370