PT-2026-49057 · Fleet · Fleet
CVE-2026-46371
·
Published
2026-06-12
·
Updated
2026-08-26
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fleet (affected versions not specified)
Description
An issue in the Apple MDM commands listing endpoint allows authenticated users with the Observer role to extract sensitive data from joined database tables, such as host enrollment secrets and Apple Push Notification Service (APNS) tokens. This is possible because the endpoint uses a deprecated helper that fails to validate the
order key parameter against a column allowlist, enabling a cursor-based binary search oracle. By manipulating the order key and the after pagination parameter, an attacker can determine the values of columns in the hosts and nano enrollments tables character by character, even though the values are not returned in the response body. This could allow an attacker to impersonate enrolled hosts to osquery and Orbit endpoints, submit fabricated data, and retrieve pending scripts. The exploitation requires Apple MDM to be enabled and at least one queued MDM command to exist. The vulnerable endpoint is GET /api/v1/fleet/mdm/apple/commands and the vulnerable parameter is order key.Recommendations
Restrict the Observer role to fully trusted users.
Rotate
node key and orbit node key for any host suspected of exposure by re-enrolling the affected hosts.Exploit
Fix
Information Disclosure
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fleet