CVE-2026-25963: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-25963 is a broken authorization vulnerability in Fleet, an open-source device management platform, that allows a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. It affects all Fleet versions prior to 4.80.1 and was disclosed on February 26, 2026, via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) as assessed by NVD, and a CVSS v4.0 base score of 1.2 (Low) as assessed by the CNA (GitHub) (Github Advisory, Fleet Advisory).

Technical details

The root cause is an incorrect authorization check (CWE-863) in Fleet's certificate template batch deletion API endpoint (DeleteCertificateTemplateSpecs). The endpoint validated authorization using a user-supplied teamID parameter to confirm the requester had write access to that team, but it did not verify that the certificate template IDs submitted in the deletion request actually belonged to that team. An authenticated team administrator could therefore supply their own teamID for authorization while including certificate template IDs from other teams in the batch deletion payload, causing cross-team deletion. The fix, introduced in commit d27d036, adds a new datastore method GetCertificateTemplatesByIdsAndTeam that queries templates filtered by both the provided IDs and the authorized teamID, then compares the count of returned records against the requested IDs to detect and reject cross-team deletions (Fleet Advisory, Patch Commit).

Impact

Successful exploitation allows a malicious or compromised team administrator to delete certificate templates owned by other teams within the same Fleet instance, disrupting certificate-based workflows including device enrollment, Wi-Fi authentication (e.g., 802.1X), VPN access, and other certificate-dependent configurations for the affected teams. The vulnerability has no confidentiality impact — no sensitive data is exposed — and does not enable privilege escalation or compromise of Fleet's control plane. Impact is strictly limited to the integrity and availability of certificate templates across teams (Fleet Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires the attacker to already hold a team administrator role within the Fleet instance, significantly limiting the attack surface. The EPSS score is approximately 0.029–0.04%, placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was responsibly disclosed by researcher @secfox-ai (GitHub: prateek-0490) (Github Advisory, Fleet Advisory).

Exploitation steps

  1. Obtain team administrator credentials: The attacker must already possess or compromise a valid Fleet team administrator account for at least one team within the target Fleet instance.
  2. Enumerate certificate template IDs: Using the Fleet API or UI, the attacker lists certificate templates visible to their own team to understand the ID numbering scheme. They may also attempt to enumerate IDs belonging to other teams by probing the API.
  3. Craft a malicious batch deletion request: The attacker constructs an API request to the certificate template batch deletion endpoint, supplying their own authorized teamID in the request parameters while including certificate template IDs that belong to other teams in the deletion payload.
  4. Submit the request: The attacker sends the crafted request to the Fleet API. In vulnerable versions, the server authorizes the request based solely on the supplied teamID without verifying template ownership, and proceeds to delete the cross-team templates.
  5. Impact realized: Certificate templates from other teams are permanently deleted, disrupting device enrollment, Wi-Fi authentication, VPN access, or other certificate-dependent workflows for the affected teams (Fleet Advisory, Patch Commit).

Indicators of compromise

  • Logs: Fleet API access logs showing batch deletion requests to the certificate template deletion endpoint where the teamID parameter does not match the team ownership of the deleted template IDs; repeated deletion requests from a single team administrator account targeting template IDs outside their team's range.
  • Application Events: Unexpected disappearance of certificate templates from teams whose administrators did not initiate deletions; certificate-based workflow failures (device enrollment errors, Wi-Fi/VPN authentication failures) across teams following suspicious API activity.
  • Audit Trail: Fleet audit log entries recording DeleteCertificateTemplateSpecs actions by a team administrator account against template IDs not associated with their team.

Mitigation and workarounds

Fleet has released version 4.80.1, which patches this vulnerability by adding server-side verification that all certificate template IDs in a batch deletion request belong to the authorized team before proceeding with deletion. Organizations unable to upgrade immediately should restrict certificate template management permissions to the minimum necessary users and avoid delegating team administrator roles broadly. Contacting Fleet at security@fleetdm.com or via the #fleet channel in the osquery Slack is recommended for further guidance (Fleet Advisory).

Community reactions

The vulnerability was responsibly reported by researcher @secfox-ai and acknowledged by Fleet in the official advisory. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified. The issue was detected by Qualys (detection ID 761789) and indexed by standard vulnerability databases shortly after disclosure.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management