CVE-2026-34387Disclosure(fleetdm / fleet)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fleetdm fleet systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package. Version 4.81.1 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fleet

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
fleet

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-05-02: 1Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-14: 103-2703-2805-0205-14
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-281
Disclosure1
2026-05-021
Patch1
2026-05-141
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Fleet, Command Injection, #CVE-2026-34387 (Critical) https://dailycve.com/fleet-command-injection-cve-2026-34387-critical/

    Post summary

    The post announces a critical command injection vulnerability (CVE-2026-34387) affecting Fleet, but provides no further technical details, exploit code, or remediation guidance.

    0000044
    202 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    Fleet CVE-2026-34387: Critical command injection via crafted package uninstall. Root/SYSTEM compromise. Patch to 4.81.1. Now. #CVE #CommandInjection #DevSecOps #CVE #devops #developers #linux #git #github #gitlab #infosec Info: https://www.valtersit.com/cve/2026/03/cve-2026-34387/

    Post summary

    CVE-2026-34387 is a critical command injection flaw in Fleet that allows privilege escalation through a crafted package uninstall. A patch to version 4.81.1 is available and should be applied immediately.

    0000050
    889 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34387 Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achie… https://www.cve.org/CVERecord?id=CVE-2026-34387

    Post summary

    The post announces a command injection vulnerability in Fleet (prior to v4.81.1) and directs readers to the CVE record, but offers no PoC, exploit, active exploitation, or patch details.

    00000152
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34387 - Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts Intel Report: https://ift.tt/3Gv4Ans

    Post summary

    An alert notes CVE-2026-34387 as an OS command injection vulnerability in fleet uninstall scripts, presenting only technical details and a reference to an intel report, without evidence of active exploitation, a PoC, or mitigation.

    0000081
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfleetdmfleet---

Explore more