← Vulnerability feed

Vulnerability record · CVE-2026-24000 · published 14 May 2026

CVE-2026-24000: Fleetdm fleet authentication bypass by spoofing vulnerability

Fleetdm · Fleet

Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass per-IP rate limiting controls. Fleet determines a client’s public IP address using HTTP headers such as X-Forwarded-For, X-Real-IP, and/or True-Client-IP. These headers were trusted without validation. An attacker could supply arbitrary values in these headers, causing Fleet to treat each request as originating from a different IP address. This could allow an attacker to bypass per-IP rate limits and increase the effectiveness of brute-force or password-spraying attempts against authentication endpoints. This issue does not allow authentication bypass, privilege escalation, data exposure, or remote code execution on its own. Version 4.80.1 contains a patch. As a workaround, run Fleet behind a trusted reverse proxy or load balancer that overwrites client IP headers.

6.9 CVSS 4.0 Medium EPSS 0.43% · top 65.3% CWE-290 · Authentication bypass by spoofing
6.9CVSS 4.0 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass per-IP rate limiting controls. Fleet determines a client’s public IP address using HTTP headers such as X-Forwarded-For, X-Real-IP, and/or True-Client-IP. These headers were trusted without validation. An attacker could supply arbitrary values in these headers, causing Fleet to treat each request as originating from a different IP address. This could allow an attacker to bypass per-IP rate limits and increase the effectiveness of brute-force or password-spraying attempts against authentication endpoints. This issue does not allow authentication bypass, privilege escalation, data exposure, or remote code execution on its own. Version 4.80.1 contains a patch. As a workaround, run Fleet behind a trusted reverse proxy or load balancer that overwrites client IP headers.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-24000 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-26276Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may…EPSS 2.2%9.3CVE-2026-23518Fleetdm fleet improper verification of cryptographic signature vulnerabilityFleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows …EPSS 0.26%8.7CVE-2026-26062Fleetdm fleet improper input validation vulnerabilityFleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `Publi…EPSS 0.54%8.7CVE-2026-26061Fleetdm fleet allocation without limits vulnerabilityFleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies wi…EPSS 0.48%8.2CVE-2026-24899Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authenticatio…EPSS 0.38%8.2CVE-2026-23998Fleetdm fleet improper certificate validation vulnerabilityFleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requ…EPSS 0.21%8.1CVE-2022-24841Fleetdm fleet improper access control vulnerabilityfleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho…EPSS 0.85%7.8CVE-2026-27806Fleetdm fleet os command injection vulnerabilityFleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local u…EPSS 0.11%

Source: NIST National Vulnerability Database (record CVE-2026-24000), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.