CVE-2026-27465Disclosure(fleetdm / fleet)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorized access to Google Calendar resources associated with the service account. Fleet returns configuration data through an API endpoint that is accessible to authenticated users, including those with the lowest-privilege “Observer” role. In affected versions, Google Calendar service account credentials were not properly obfuscated before being returned. As a result, a low-privilege user could retrieve the service account’s private key material. Depending on how the Google Calendar integration is configured, this could allow unauthorized access to calendar data or other Google Workspace resources associated with the service account. This issue does not allow escalation of privileges within Fleet or access to device management functionality. Version 4.80.1 patches the issue. If an immediate upgrade is not possible, administrators should remove the Google Calendar integration from Fleet and rotate the affected Google service account credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fleet

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
fleet

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-26: 3Technical Details · 2026-02-26: 302-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27465: Fleet's Open Secret: The Google Calendar Key Leak A deep dive into CVE-2026-27465, where Fleet Device Management inadvertently exposed Google Calendar Service Account private keys to low-privileged users via the application configurati... https://cvereports.com/reports/CVE-2026-27465

    Post summary

    The report explains how Fleet Device Management inadvertently exposed Google Calendar service account private keys to low‑privileged users via configuration, but it does not mention a PoC, exploit, patch, or active exploitation.

    0000048
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27465 Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service accoun… https://www.cve.org/CVERecord?id=CVE-2026-27465

    Post summary

    The text announces CVE-2026-27465, describing a configuration API flaw in Fleet that could expose Google Calendar service accounts, but it does not provide a PoC, exploit, or patch details.

    00000101
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27465 Information Disclosure in Fleet Device Management Software Google Calendar Integration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27465

    Post summary

    A new information disclosure vulnerability (CVE-2026-27465) affecting fleet device management software's Google Calendar integration has been identified.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfleetdmfleet---

Explore more