Fleet · Fleet · CVE-2026-48786
**Name of the Vulnerable Software and Affected Versions**
Fleet versions prior to 4.87.0
**Description**
The target search endpoint `POST /api/latest/fleet/targets` fails to sanitize data for users with Observer, Observer+, or Technician roles. This allows these users to retrieve unmasked team enroll secrets and full team configurations, including credential-bearing agent options such as AWS secret access keys, proxy passwords, or session tokens. While other team-facing endpoints mask these fields, this specific endpoint does not, potentially allowing unauthorized hosts to be enrolled into a team or the theft of sensitive credentials.
**Recommendations**
Update to version 4.87.0.
Rotate team enroll secrets for any team that may have been exposed.
Rotate any credentials stored in team agent options, including AWS keys, proxy passwords, and session tokens.
Restrict Observer and Technician roles to fully trusted users.