CVE-2026-34386: Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin

Published Mar 27, 2026
·
Updated

Summary

A SQL Injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject arbitrary content into team configs via direct API calls.

Impact

An authenticated user with Team Admin or Global Admin role can exploit a flaw in how user-supplied input is handled during MDM bootstrap package configuration. Insufficient server-side input validation allows crafted input to manipulate database queries in unintended ways.

Successful exploitation could enable cross-team data corruption, exfiltration of sensitive information such as password hashes and API tokens, and potential privilege escalation. Exploitation requires authentication with team or global admin privileges and MDM to be enabled.

This issue does not affect instances where Apple MDM is disabled.

Workarounds

If an immediate upgrade is not possible, affected Fleet users should temporarily disable Apple MDM or limit admin roles.

For more information

If there are any questions or comments about this advisory:

Send an email to security@fleetdm.com

Join #fleet in osquery Slack

Credits

Fleet thanks the Secfox Research Team (@secfox-ai) for responsibly reporting this issue.

Other sources

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject arbitrary content into team configs via direct API calls. Version 4.81.0 patches the issue.

NVD

Affected Software

3 affected componentsFixes available
fleetdm fleet<4.81.0
go/github.com/fleetdm/fleet/v4<4.81.0
4.81.0
fleetdm fleet<4.81.0

Event History

Mar 27, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 30, 2026
Advisory Published
via GitHub·07:18 PM
Data Sourced
via GitHub·07:18 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-34386?

CVE-2026-34386 is a high severity SQL Injection vulnerability affecting Fleet's MDM bootstrap package.

2

How do I fix CVE-2026-34386?

To fix CVE-2026-34386, you should upgrade to Fleet version 4.81.0 or later.

3

Who is affected by CVE-2026-34386?

CVE-2026-34386 affects authenticated users with Team Admin or Global Admin privileges in Fleet.

4

What type of vulnerability is CVE-2026-34386?

CVE-2026-34386 is classified as a SQL Injection vulnerability.

5

Can CVE-2026-34386 be exploited remotely?

CVE-2026-34386 requires authenticated access, so it cannot be exploited remotely without proper credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203