
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25963 is a broken authorization vulnerability in Fleet, an open-source device management platform, that allows a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. It affects all Fleet versions prior to 4.80.1 and was disclosed on February 26, 2026, via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) as assessed by NVD, and a CVSS v4.0 base score of 1.2 (Low) as assessed by the CNA (GitHub) (Github Advisory, Fleet Advisory).
The root cause is an incorrect authorization check (CWE-863) in Fleet's certificate template batch deletion API endpoint (DeleteCertificateTemplateSpecs). The endpoint validated authorization using a user-supplied teamID parameter to confirm the requester had write access to that team, but it did not verify that the certificate template IDs submitted in the deletion request actually belonged to that team. An authenticated team administrator could therefore supply their own teamID for authorization while including certificate template IDs from other teams in the batch deletion payload, causing cross-team deletion. The fix, introduced in commit d27d036, adds a new datastore method GetCertificateTemplatesByIdsAndTeam that queries templates filtered by both the provided IDs and the authorized teamID, then compares the count of returned records against the requested IDs to detect and reject cross-team deletions (Fleet Advisory, Patch Commit).
Successful exploitation allows a malicious or compromised team administrator to delete certificate templates owned by other teams within the same Fleet instance, disrupting certificate-based workflows including device enrollment, Wi-Fi authentication (e.g., 802.1X), VPN access, and other certificate-dependent configurations for the affected teams. The vulnerability has no confidentiality impact — no sensitive data is exposed — and does not enable privilege escalation or compromise of Fleet's control plane. Impact is strictly limited to the integrity and availability of certificate templates across teams (Fleet Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires the attacker to already hold a team administrator role within the Fleet instance, significantly limiting the attack surface. The EPSS score is approximately 0.029–0.04%, placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) (Github Advisory, Fleet Advisory).
teamID in the request parameters while including certificate template IDs that belong to other teams in the deletion payload.teamID without verifying template ownership, and proceeds to delete the cross-team templates.teamID parameter does not match the team ownership of the deleted template IDs; repeated deletion requests from a single team administrator account targeting template IDs outside their team's range.DeleteCertificateTemplateSpecs actions by a team administrator account against template IDs not associated with their team.Fleet has released version 4.80.1, which patches this vulnerability by adding server-side verification that all certificate template IDs in a batch deletion request belong to the authorized team before proceeding with deletion. Organizations unable to upgrade immediately should restrict certificate template management permissions to the minimum necessary users and avoid delegating team administrator roles broadly. Contacting Fleet at security@fleetdm.com or via the #fleet channel in the osquery Slack is recommended for further guidance (Fleet Advisory).
The vulnerability was responsibly reported by researcher @secfox-ai and acknowledged by Fleet in the official advisory. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified. The issue was detected by Qualys (detection ID 761789) and indexed by standard vulnerability databases shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."