CVE-2026-101046: Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints

Published Sep 27, 2026
·
Updated

Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToSQL interpolated the caller-supplied sort/order key into the SQL ORDER BY clause without an allowlist, so an authenticated user with read access to Activity could order results by arbitrary columns. The impact is read-only and bounded to columns on the activitypast table that are not otherwise returned in these responses (e.g. details), allowing their values to be inferred through the resulting sort order; there is no write access, privilege escalation, or reachability of nodekey or other host-join columns through these endpoints. Fixed in 4.89.0, which removes the deprecated helper and passes the sort column through SanitizeColumn.

Affected Software

1 affected component
Fleet Fleet<4.89.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Fleet to a version that resolves this vulnerability.

    Fixed in 4.89.0

Event History

Sep 27, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Oct 30, 58709
Event
via NVD·06:14 AM

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated and have read access to Activity. The affected endpoints are network-accessible, but unauthenticated users cannot exploit the described behavior.

2

What information can be exposed through the injection?

The impact is limited to read-only inference of values in activity_past columns that are not normally returned by these responses, such as details, based on sort order. The issue does not provide write access, privilege escalation, or access to node_key or host-join columns.

3

Are installations affected by default?

An installation is affected if it runs a Fleet version before 4.89.0 and permits a user to read Activity through the affected activity-list endpoints. The provided information does not specify any additional configuration requirement.

4

What should be done if an immediate upgrade is not possible?

Restrict Activity read access to trusted users, since that permission is required for exploitation. Upgrading to Fleet 4.89.0 removes the deprecated helper and sanitizes the sort column.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203