PT-2026-76561 · Fleet · Fleet

·

CVE-2026-48786

·

Published

2026-08-12

·

Updated

2026-09-04

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.87.0
Description The target search endpoint POST /api/latest/fleet/targets fails to sanitize data for users with Observer, Observer+, or Technician roles. This allows these users to retrieve unmasked team enroll secrets and full team configurations, including credential-bearing agent options such as AWS secret access keys, proxy passwords, or session tokens. While other team-facing endpoints mask these fields, this specific endpoint does not, potentially allowing unauthorized hosts to be enrolled into a team or the theft of sensitive credentials.
Recommendations Update to version 4.87.0. Rotate team enroll secrets for any team that may have been exposed. Rotate any credentials stored in team agent options, including AWS keys, proxy passwords, and session tokens. Restrict Observer and Technician roles to fully trusted users.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48786
GHSA-88P2-JJ8W-J8QG
GO-2026-6220
OPENSUSE-SU-2026:21761-1

Affected Products

Fleet