PT-2026-49057 · Fleet · Fleet

CVE-2026-46371

·

Published

2026-06-12

·

Updated

2026-08-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fleet (affected versions not specified)
Description An issue in the Apple MDM commands listing endpoint allows authenticated users with the Observer role to extract sensitive data from joined database tables, such as host enrollment secrets and Apple Push Notification Service (APNS) tokens. This is possible because the endpoint uses a deprecated helper that fails to validate the order key parameter against a column allowlist, enabling a cursor-based binary search oracle. By manipulating the order key and the after pagination parameter, an attacker can determine the values of columns in the hosts and nano enrollments tables character by character, even though the values are not returned in the response body. This could allow an attacker to impersonate enrolled hosts to osquery and Orbit endpoints, submit fabricated data, and retrieve pending scripts. The exploitation requires Apple MDM to be enabled and at least one queued MDM command to exist. The vulnerable endpoint is GET /api/v1/fleet/mdm/apple/commands and the vulnerable parameter is order key.
Recommendations Restrict the Observer role to fully trusted users. Rotate node key and orbit node key for any host suspected of exposure by re-enrolling the affected hosts.

Exploit

Fix

Information Disclosure

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46371
GHSA-X4QR-QW6H-WVXQ
GO-2026-5739
OPENSUSE-SU-2026:21483-1

Affected Products

Fleet