THREAT OPS › Threat News › [NVD] CVE-2026-46370 (MEDIUM 6.5) — Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment sec
[NVD] CVE-2026-46370 (MEDIUM 6.5) — Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment sec
CVE-2026-46370 CVSS: 6.5 MEDIUM Published: 2026-08-26T20:17:23.327
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-order oracle. The endpoint accep
Indicators of compromise
- CVE-2026-46370cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-46370