← Vulnerability feed

Vulnerability record · CVE-2026-23518 · published 21 January 2026

CVE-2026-23518: Fleetdm fleet improper verification of cryptographic signature vulnerability

Fleetdm · Fleet

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could accept attacker-controlled identity claims, enabling enrollment of unauthorized devices under arbitrary Azure AD user identities. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

9.3 CVSS 4.0 Critical EPSS 0.26% · top 84.3% CWE-347 · Improper verification of cryptographic signature
9.3CVSS 4.0 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could accept attacker-controlled identity claims, enabling enrollment of unauthorized devices under arbitrary Azure AD user identities. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23518 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-26276Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may…EPSS 2.2%8.7CVE-2026-26062Fleetdm fleet improper input validation vulnerabilityFleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `Publi…EPSS 0.54%8.7CVE-2026-26061Fleetdm fleet allocation without limits vulnerabilityFleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies wi…EPSS 0.48%8.2CVE-2026-24899Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authenticatio…EPSS 0.38%8.2CVE-2026-23998Fleetdm fleet improper certificate validation vulnerabilityFleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requ…EPSS 0.21%8.1CVE-2022-24841Fleetdm fleet improper access control vulnerabilityfleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho…EPSS 0.85%7.8CVE-2026-27806Fleetdm fleet os command injection vulnerabilityFleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local u…EPSS 0.11%6.9CVE-2026-46356Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attac…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2026-23518), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.