CVE-2026-27465: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27465 is a sensitive credential disclosure vulnerability in Fleet, an open-source device management platform, where Google Calendar service account private key material is exposed to low-privilege authenticated users via the configuration API. It affects all Fleet versions prior to 4.80.1 and was disclosed on February 26, 2026, by researcher @secfox-ai (prateek-0490) via responsible disclosure. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) per NVD, though the GitHub Advisory rates it High with a CVSS v4 score of 7.1 (GitHub Advisory, Fleet Advisory).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor): Fleet's configuration API endpoint returned Google Calendar integration settings — including the service account's private key JSON — without properly obfuscating the credential material before sending it to the client (GitHub Advisory). The endpoint is accessible to all authenticated users, including those with the lowest-privilege "Observer" role, requiring only valid low-privilege credentials to exploit over the network with no user interaction. The fix, implemented in commit 23fc680, introduced a GoogleCalendarApiKey wrapper type that obfuscates key values (replacing them with "********") in GET responses, and updated the frontend to detect and handle the masked placeholder without re-submitting it (Patch Commit).

Impact

A successfully exploited vulnerability allows any authenticated Fleet user — even those with the read-only Observer role — to retrieve the Google Calendar service account's private key material in plaintext. This credential exposure could enable unauthorized access to Google Calendar data and potentially other Google Workspace resources associated with the service account, depending on the permissions granted to that account. Critically, this vulnerability does not permit privilege escalation within Fleet itself or access to device management functionality, limiting the blast radius to Google Workspace resources (Fleet Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.05% (18th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid low-privilege Fleet account, making it trivially simple for any insider or compromised Observer-role user to execute.

Exploitation steps

  1. Obtain low-privilege access: Acquire or compromise any Fleet account with at least the "Observer" role — the lowest privilege level in Fleet.
  2. Authenticate to the Fleet API: Use the Observer credentials to authenticate to the Fleet instance and obtain a valid session token or API key.
  3. Query the configuration API endpoint: Send an authenticated GET request to Fleet's configuration API endpoint (e.g., GET /api/v1/fleet/config) that returns application configuration data including integrations.
  4. Extract Google Calendar credentials: Parse the JSON response to locate the integrations.google_calendar field, which in affected versions (< 4.80.1) returns the full api_key_json object including the service account's private_key and client_email in plaintext.
  5. Abuse the service account: Use the extracted private key material to authenticate as the Google service account and access Google Calendar data or other Google Workspace resources associated with that account (Fleet Advisory, Patch Commit).

Indicators of compromise

  • Logs: Fleet API access logs showing GET requests to /api/v1/fleet/config (or equivalent configuration endpoints) from Observer-role user accounts, particularly if repeated or from unexpected IP addresses.
  • Logs: Google Workspace audit logs showing authentication events or API calls from the Fleet service account originating from IP addresses not associated with the Fleet server infrastructure.
  • Network: Outbound connections from the Fleet server to Google APIs (e.g., calendar.googleapis.com, oauth2.googleapis.com) at unusual times or volumes inconsistent with normal Fleet operation.
  • Google Workspace: Unexpected calendar event reads, modifications, or access to Google Workspace resources by the Fleet service account outside of normal Fleet-initiated operations.

Mitigation and workarounds

Upgrade Fleet to version 4.80.1 or later, which obfuscates Google Calendar service account credentials in API responses (Fleet Advisory). If an immediate upgrade is not possible, administrators should remove the Google Calendar integration from Fleet's configuration to prevent credential exposure, and immediately rotate the affected Google service account credentials (generate a new key pair and revoke the old one in Google Cloud Console). After patching or rotating credentials, audit Fleet API access logs for any Observer-role users who may have queried the configuration endpoint while the vulnerability was present.

Community reactions

The vulnerability was responsibly reported by researcher @secfox-ai (GitHub: prateek-0490) and credited in the Fleet security advisory (Fleet Advisory). The issue received routine coverage from vulnerability tracking services including Vulners, CVEFeed, and CIRCL, with no notable broader media coverage or significant community debate, consistent with its limited scope and low exploitation risk.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management