CVE-2026-23999: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-23999 is a predictable PIN generation vulnerability in Fleet, an open-source device management platform. In versions prior to 4.80.1, Fleet generated 6-digit device lock and wipe PINs using a deterministic algorithm based solely on the current Unix timestamp, with no secret key or additional entropy. This means an attacker with physical access to a locked device and knowledge of the approximate lock time could theoretically predict the correct PIN within a limited search window. The vulnerability was disclosed on February 26, 2026, and affects all Fleet versions before 4.80.1. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 score of 0.6 (Low) (GitHub Advisory, Fleet Security Advisory).

Technical details

The root cause is classified as CWE-330 (Use of Insufficiently Random Values). The vulnerable GenerateRandomPin() function in server/mdm/apple/util.go derived the 6-digit PIN by using time.Now().Unix() as the sole input — effectively treating the current Unix timestamp as a counter — then hashing it with SHA-256 and truncating to the desired digit length. Because no cryptographic secret or additional entropy source was incorporated, the output is fully deterministic and reproducible by anyone who knows the approximate time the lock command was issued. The fix, introduced in commit 05ca069, replaces the timestamp-based counter with crypto/rand.Read() to generate 16 bytes of cryptographically secure random data before hashing (Fleet Security Advisory, Patch Commit).

Impact

Successful exploitation could allow an attacker with physical possession of a Fleet-managed locked device to bypass the device lock PIN and gain unauthorized access to the device and its data, resulting in a high confidentiality impact. The vulnerability does not affect integrity or availability, and it cannot be exploited remotely, nor does it enable fleet-wide compromise or bypass of Fleet server authentication controls. The practical impact is further constrained by OS-enforced PIN entry rate limiting, the need to spread attempts over multiple days, and the likelihood that a wipe command would complete before sufficient PIN attempts could be made (GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Fleet Security Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038% (Feedly) to 0.023% (GitHub Advisory), placing it in a low percentile for exploitation probability. No threat actor attribution has been reported. The vulnerability was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target organization using Fleet for device management (versions < 4.80.1) and determine that a device has been remotely locked via Fleet's MDM lock command.
  2. Obtain physical access: Gain physical possession of the locked Fleet-managed device (e.g., a lost, stolen, or unattended macOS device).
  3. Determine approximate lock time: Estimate the Unix timestamp at which the lock command was issued. This could be inferred from device activity logs, organizational schedules, or social engineering to learn when the lock was triggered.
  4. Generate candidate PINs: Write a script that iterates over a range of Unix timestamps centered on the estimated lock time, applying the same SHA-256-based truncation algorithm used by the vulnerable GenerateRandomPin() function to produce a list of candidate 6-digit PINs.
  5. Attempt PIN entry: Manually enter candidate PINs on the locked device, respecting OS-enforced rate limiting (which may require spreading attempts over multiple days to avoid lockout or wipe triggers).
  6. Unlock device: If the correct PIN is entered before a wipe operation completes, the attacker gains access to the device and its stored data (Fleet Security Advisory, Patch Commit).

Mitigation and workarounds

Fleet has released version 4.80.1, which patches this vulnerability by replacing the timestamp-based PIN generation with cryptographically secure random bytes via crypto/rand.Read(). Organizations should upgrade to Fleet 4.80.1 or later as soon as possible, particularly those operating in environments with limited physical device security controls. There are no known workarounds for this issue — upgrading is the only remediation (Fleet Security Advisory, Patch Commit).

Community reactions

The vulnerability was responsibly reported by researcher @secfox-ai (prateek-0490) and acknowledged by Fleet in their security advisory published February 26, 2026. Fleet's advisory characterized the severity as "Moderate" and emphasized the significant practical constraints on exploitation. No notable broader media coverage or significant community controversy has been observed beyond standard vulnerability database indexing and aggregator coverage (Fleet Security Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management