CVE-2026-34391: Fleet Vulnerable to Windows MDM cross-device command disclosure
Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet. Version 4.81.1 patches the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34391?
CVE-2026-34391 is classified as a high severity vulnerability due to the risk of sensitive command exposure.
How do I fix CVE-2026-34391?
To fix CVE-2026-34391, upgrade Fleet to version 4.81.1 or later.
What type of vulnerability is CVE-2026-34391?
CVE-2026-34391 is a cross-device command disclosure vulnerability in Fleet's Windows MDM functionality.
Who is affected by CVE-2026-34391?
Any user running Fleet versions prior to 4.81.1 on Windows MDM is affected by CVE-2026-34391.
What kind of information could be exposed due to CVE-2026-34391?
CVE-2026-34391 could potentially expose sensitive MDM commands intended for other devices.