PT-2026-76561 · Fleet · Fleet
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fleet versions prior to 4.87.0
Description
The target search endpoint
POST /api/latest/fleet/targets fails to sanitize data for users with Observer, Observer+, or Technician roles. This allows these users to retrieve unmasked team enroll secrets and full team configurations, including credential-bearing agent options such as AWS secret access keys, proxy passwords, or session tokens. While other team-facing endpoints mask these fields, this specific endpoint does not, potentially allowing unauthorized hosts to be enrolled into a team or the theft of sensitive credentials.Recommendations
Update to version 4.87.0.
Rotate team enroll secrets for any team that may have been exposed.
Rotate any credentials stored in team agent options, including AWS keys, proxy passwords, and session tokens.
Restrict Observer and Technician roles to fully trusted users.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fleet