CVE-2026-23517: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-23517 is a broken access control vulnerability in Fleet, an open-source device management platform, affecting the Go package github.com/fleetdm/fleet. The flaw allows any authenticated user — including those with the lowest-privilege "Observer" role — to access the server's debug/pprof profiling endpoints without proper role-based authorization checks. It was disclosed on January 20, 2026, and affects Fleet versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 6.3 (Medium) (Github Advisory, Fleet Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization). Fleet's debugAuthenticationMiddleware in server/service/debug_handler.go only checked whether a user could perform general actions (CanPerformActions()), but did not verify that the user held the Admin global role before granting access to the /debug/pprof endpoints. The fix, introduced in commit 5c030e3, adds an additional check requiring v.User.GlobalRole == nil || *v.User.GlobalRole != fleet.RoleAdmin, restricting access to global administrators only. Exploitation requires only a valid authenticated session — no elevated privileges are needed — making it trivially exploitable by any registered user (Fleet Advisory, Fix Commit).

Impact

Successful exploitation allows low-privilege users to access sensitive server internals exposed via Go's pprof profiling endpoints, including runtime profiling data, goroutine stacks, heap allocations, and in-memory application state. Additionally, attackers can trigger CPU-intensive profiling operations (e.g., CPU profiles, trace captures) that are resource-heavy and could degrade or deny service to the Fleet server. The confidentiality impact is high due to exposure of internal diagnostics, and the availability impact is high due to the potential for denial of service through repeated profiling requests (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.038% (0.000380), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is straightforward for any authenticated Fleet user, requiring only a valid session token and knowledge of the /debug/pprof endpoint paths.

Exploitation steps

  1. Obtain credentials: Acquire any valid Fleet user account, including the lowest-privilege "Observer" role — this could be a free trial account, a compromised low-privilege credential, or a self-registered account if open registration is enabled.
  2. Authenticate: Log in to the Fleet instance and obtain a valid session token (Bearer token) via the Fleet API or web UI.
  3. Access pprof endpoints: Send an authenticated HTTP GET request to the /debug/pprof/ endpoint, e.g.:
    GET /debug/pprof/heap HTTP/1.1
    Host: <fleet-server>
    Authorization: BEARER <session_token>
  4. Exfiltrate diagnostics: Parse the returned profiling data to extract runtime memory state, goroutine stacks, or other internal application details that may reveal sensitive configuration or operational information.
  5. Trigger denial of service: Repeatedly request CPU-intensive profiles (e.g., /debug/pprof/profile?seconds=30) to consume server CPU resources and degrade availability for legitimate users (Fleet Advisory, Fix Commit).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /debug/pprof/, /debug/pprof/heap, /debug/pprof/goroutine, /debug/pprof/profile, or /debug/pprof/cmdline from non-administrative user sessions; repeated requests to /debug/pprof/profile with long seconds parameters indicating DoS attempts.
  • Logs: Fleet access logs showing requests to /debug/* endpoints authenticated with Observer or Maintainer role session tokens; HTTP 200 responses to /debug/pprof/ paths from low-privilege accounts (pre-patch behavior).
  • Process: Elevated CPU utilization on the Fleet server process coinciding with requests to /debug/pprof/profile or /debug/pprof/trace endpoints.

Mitigation and workarounds

Fleet has released patched versions addressing this issue: 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3. Upgrading to the appropriate patched version for your release branch is the recommended remediation. If an immediate upgrade is not possible, restrict access to the /debug/pprof endpoints by placing them behind an IP allowlist, limiting access to trusted administrative networks only. Contact Fleet at security@fleetdm.com or the #fleet channel in the osquery Slack for additional guidance (Fleet Advisory).

Community reactions

The vulnerability was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) and remediated by Fleet developer iansltx. Fleet published the advisory on January 20, 2026, and credited the reporter publicly. No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability tracking (Fleet Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management