PT-2026-80753 · Fleet+1 · Fleet+1
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Fleet (affected versions not specified)
Description
A SQL injection exists in the Okta conditional access integration. An attacker controlling a single enrolled host can provide a value via the host agent that is used in a database query without proper parameterization. This allows the attacker to read or modify arbitrary data in the database, including stored session tokens. If session tokens are disclosed, they can be replayed to obtain global administrator privileges, potentially leading to remote code execution on all enrolled hosts through the execution of scripts.
Recommendations
Disable the Okta conditional access integration as a temporary workaround.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fleet
Okta