
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23999 is a predictable PIN generation vulnerability in Fleet, an open-source device management platform. In versions prior to 4.80.1, Fleet generated 6-digit device lock and wipe PINs using a deterministic algorithm based solely on the current Unix timestamp, with no secret key or additional entropy. This means an attacker with physical access to a locked device and knowledge of the approximate lock time could theoretically predict the correct PIN within a limited search window. The vulnerability was disclosed on February 26, 2026, and affects all Fleet versions before 4.80.1. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 score of 0.6 (Low) (GitHub Advisory, Fleet Security Advisory).
The root cause is classified as CWE-330 (Use of Insufficiently Random Values). The vulnerable GenerateRandomPin() function in server/mdm/apple/util.go derived the 6-digit PIN by using time.Now().Unix() as the sole input — effectively treating the current Unix timestamp as a counter — then hashing it with SHA-256 and truncating to the desired digit length. Because no cryptographic secret or additional entropy source was incorporated, the output is fully deterministic and reproducible by anyone who knows the approximate time the lock command was issued. The fix, introduced in commit 05ca069, replaces the timestamp-based counter with crypto/rand.Read() to generate 16 bytes of cryptographically secure random data before hashing (Fleet Security Advisory, Patch Commit).
Successful exploitation could allow an attacker with physical possession of a Fleet-managed locked device to bypass the device lock PIN and gain unauthorized access to the device and its data, resulting in a high confidentiality impact. The vulnerability does not affect integrity or availability, and it cannot be exploited remotely, nor does it enable fleet-wide compromise or bypass of Fleet server authentication controls. The practical impact is further constrained by OS-enforced PIN entry rate limiting, the need to spread attempts over multiple days, and the likelihood that a wipe command would complete before sufficient PIN attempts could be made (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Fleet Security Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038% (Feedly) to 0.023% (GitHub Advisory), placing it in a low percentile for exploitation probability. No threat actor attribution has been reported. The vulnerability was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) (GitHub Advisory).
GenerateRandomPin() function to produce a list of candidate 6-digit PINs.Fleet has released version 4.80.1, which patches this vulnerability by replacing the timestamp-based PIN generation with cryptographically secure random bytes via crypto/rand.Read(). Organizations should upgrade to Fleet 4.80.1 or later as soon as possible, particularly those operating in environments with limited physical device security controls. There are no known workarounds for this issue — upgrading is the only remediation (Fleet Security Advisory, Patch Commit).
The vulnerability was responsibly reported by researcher @secfox-ai (prateek-0490) and acknowledged by Fleet in their security advisory published February 26, 2026. Fleet's advisory characterized the severity as "Moderate" and emphasized the significant practical constraints on exploitation. No notable broader media coverage or significant community controversy has been observed beyond standard vulnerability database indexing and aggregator coverage (Fleet Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."