CVE-2026-26060Disclosure(fleetdm / fleet)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fleet

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
fleet

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 2Mentions · 2026-03-31: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 103-2803-31
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-282
Disclosure2
2026-03-311
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26060 Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset to… https://www.cve.org/CVERecord?id=CVE-2026-26060

    Post summary

    The post discloses a weakness in Fleet’s password management logic that existed before version 4.81.0, but provides neither a PoC nor mitigation details.

    00010176
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26060 - High Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid af... https://www.thehackerwire.com/vulnerability/CVE-2026-26060/ https://t.co/OnuJ3L3cvm

    Post summary

    The post announces a high‑severity flaw in Fleet’s password reset token logic that could let attackers retain valid tokens, but no evidence of exploitation, patches, or proof of concepts is provided.

    0000037
    163 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26060 Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset to… https://www.cve.org/CVERecord?id=CVE-2026-26060 ----- Traducción: CVE-2026-26060 Fle… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-26060, explaining a flaw in Fleet’s password reset logic that could let attackers misuse old reset tokens in versions prior to 4.81.0.

    0000043
    65 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfleetdmfleet---

Explore more