CVE-2026-26186Disclosure(fleetdm / fleet)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the `order_key` query parameter. Due to unsafe use of `goqu.I()` when constructing the `ORDER BY` clause, specially crafted input could escape identifier quoting and be interpreted as executable SQL. An authenticated attacker with access to the affected endpoint could inject SQL expressions into the underlying MySQL query. Although the injection occurs in an `ORDER BY` context, it is sufficient to enable blind SQL injection techniques that can disclose database information through conditional expressions that affect result ordering. Crafted expressions may also cause excessive computation or query failures, potentially leading to degraded performance or denial of service. No direct evidence of reliable data modification or stacked query execution was demonstrated. Version 4.80.1 fixes the issue. If an immediate upgrade is not possible, users should restrict access to the affected endpoint to trusted roles only and ensure that any user-supplied sort or column parameters are strictly allow-listed at the application or proxy layer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fleet

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fleet

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-26: 1Mentions · 2026-03-03: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-03: 102-2603-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26186 (CVSS:5.1, HIGH) is Analyzed. Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authe..https://nvd.nist.gov/vuln/detail/CVE-2026-26186 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-26186, a SQL injection flaw in Fleet before version 4.80.1, with a CVSS score of 5.1, but provides no PoC, exploit, or patch details.

    0000021
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26186 Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL express… https://www.cve.org/CVERecord?id=CVE-2026-26186

    Post summary

    The post announces a SQL injection vulnerability in Fleet device management software affecting versions prior to 4.80.1, with no mention of PoC, exploit, or patch.

    00000130
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfleetdmfleet---

Explore more