
XSS vulnerability in Fleet Windows MDM (CVE-2026-22808) We found a critical XSS flaw in Fleet's Windows MDM authentication mechanism. What this means: an attacker can craft a malicious link, trick a Fleet user into clicking it, steal their authentication token, and use it to access the Fleet API with their privileges. The worst part? They could deploy scripts to your managed hosts. Fleet manages millions of endpoints across enterprise environments. If you're running Windows MDM, this affects you. Technical breakdown: - Cross-site scripting in MDM authentication flow - Auth token extraction via crafted links - Privileged API access with stolen credentials - Remote script deployment to managed devices What to do: - Upgrade to 4.78.2 (or patched versions: 4.77.1, 4.76.2, 4.75.2, 4.53.3) - Or disable Windows MDM until you can patch Patch now: https://github.com/fleetdm/fleet/security/advisories/GHSA-gfpw-jgvr-cw4j #cybersecurity #vulnerability #MDM #infosec #CVE #Fleet #devicemanagement #securityresearch #appsec #XSS #AI #startup
Post summary
The post discloses a critical XSS flaw in Fleet Windows MDM (CVE-2026-22808), provides detailed technical insights, and gives specific patched versions with a link to the official advisory.
