CVE-2026-101046: Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints
Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToSQL interpolated the caller-supplied sort/order key into the SQL ORDER BY clause without an allowlist, so an authenticated user with read access to Activity could order results by arbitrary columns. The impact is read-only and bounded to columns on the activitypast table that are not otherwise returned in these responses (e.g. details), allowing their values to be inferred through the resulting sort order; there is no write access, privilege escalation, or reachability of nodekey or other host-join columns through these endpoints. Fixed in 4.89.0, which removes the deprecated helper and passes the sort column through SanitizeColumn.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fleetto a version that resolves this vulnerability.Fixed in 4.89.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and have read access to Activity. The affected endpoints are network-accessible, but unauthenticated users cannot exploit the described behavior.
What information can be exposed through the injection?
The impact is limited to read-only inference of values in activity_past columns that are not normally returned by these responses, such as details, based on sort order. The issue does not provide write access, privilege escalation, or access to node_key or host-join columns.
Are installations affected by default?
An installation is affected if it runs a Fleet version before 4.89.0 and permits a user to read Activity through the affected activity-list endpoints. The provided information does not specify any additional configuration requirement.
What should be done if an immediate upgrade is not possible?
Restrict Activity read access to trusted users, since that permission is required for exploitation. Upgrading to Fleet 4.89.0 removes the deprecated helper and sanitizes the sort column.