← Vulnerability feed

Vulnerability record · CVE-2026-26061 · published 27 March 2026

CVE-2026-26061: Fleetdm fleet allocation without limits vulnerability

Fleetdm · Fleet

Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending large or repeated HTTP payloads, causing excessive memory allocation and resulting in a denial-of-service (DoS) condition. Version 4.81.0 patches the issue.

8.7 CVSS 4.0 High EPSS 0.48% · top 61.0% CWE-770 · Allocation without limits
8.7CVSS 4.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending large or repeated HTTP payloads, causing excessive memory allocation and resulting in a denial-of-service (DoS) condition. Version 4.81.0 patches the issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-26061 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-26276Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may…EPSS 2.2%9.3CVE-2026-23518Fleetdm fleet improper verification of cryptographic signature vulnerabilityFleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows …EPSS 0.26%8.7CVE-2026-26062Fleetdm fleet improper input validation vulnerabilityFleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `Publi…EPSS 0.54%8.2CVE-2026-24899Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authenticatio…EPSS 0.38%8.2CVE-2026-23998Fleetdm fleet improper certificate validation vulnerabilityFleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requ…EPSS 0.21%8.1CVE-2022-24841Fleetdm fleet improper access control vulnerabilityfleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho…EPSS 0.85%7.8CVE-2026-27806Fleetdm fleet os command injection vulnerabilityFleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local u…EPSS 0.11%6.9CVE-2026-46356Fleetdm fleet authentication bypass by spoofing vulnerabilityFleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attac…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2026-26061), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.