CVE-2026-34386: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-34386 is a SQL injection vulnerability in Fleet's MDM bootstrap package configuration affecting all versions of the open-source device management software prior to 4.81.0. It allows authenticated users with Team Admin or Global Admin privileges to manipulate database queries via direct API calls, enabling unauthorized modification of team configurations, data exfiltration, and content injection. The vulnerability was published on March 27, 2026, with a patch released in version 4.81.0. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 6.3 (Medium) (Github Advisory, Fleet Advisory).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient server-side input validation when processing user-supplied input during MDM bootstrap package configuration (Github Advisory). An attacker can craft malicious input through direct API calls to the MDM bootstrap package configuration endpoint, causing the backend to interpret the input as SQL rather than data, thereby manipulating database queries in unintended ways. Exploitation requires network access, valid Team Admin or Global Admin credentials, and Apple MDM to be enabled on the Fleet instance — instances with Apple MDM disabled are not affected (Fleet Advisory). No public proof-of-concept exploit code has been identified at this time (Github Advisory).

Impact

Successful exploitation allows an authenticated attacker to modify arbitrary team configurations beyond their authorized scope, exfiltrate sensitive data from the Fleet database including password hashes and API tokens, inject arbitrary content into team configurations, and potentially escalate privileges (Fleet Advisory). The vulnerability has high impact on confidentiality, integrity, and availability of the Fleet database and team configurations. Cross-team data corruption is also a potential consequence, making this particularly dangerous in multi-tenant Fleet deployments (Github Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of reporting (Github Advisory). The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with elevated privileges (Team Admin or Global Admin), which limits the attacker pool but does not eliminate risk from insider threats or compromised admin accounts (Fleet Advisory).

Exploitation steps

  1. Reconnaissance: Identify Fleet instances running versions prior to 4.81.0 with Apple MDM enabled. Confirm admin-level access (Team Admin or Global Admin credentials) is available, either through legitimate access, credential theft, or social engineering.
  2. Authenticate to Fleet API: Use valid admin credentials to authenticate to the Fleet API and obtain a session token or API key.
  3. Target the MDM bootstrap package configuration endpoint: Identify the API endpoint responsible for MDM bootstrap package configuration (e.g., a POST/PUT endpoint for MDM bootstrap package settings).
  4. Craft malicious SQL injection payload: Construct a request with crafted input in the relevant parameter(s) that embeds SQL syntax designed to manipulate the underlying database query — for example, using UNION-based injection to extract data from other tables, or stacked queries to modify configurations.
  5. Send the crafted API request: Submit the malicious API call directly to the Fleet server, bypassing normal UI validation.
  6. Achieve objectives: Depending on the payload, extract sensitive data (password hashes, API tokens), modify team configurations across teams, or inject arbitrary content into team configs (Fleet Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual or unexpected API calls to Fleet's MDM bootstrap package configuration endpoints from admin accounts, particularly with abnormal parameter values or encoding; API requests containing SQL metacharacters (e.g., ', --, UNION, SELECT) in configuration fields.
  • Logs: Fleet API access logs showing repeated or anomalous requests to MDM bootstrap package endpoints with malformed or oversized input; database error logs indicating SQL syntax errors or unexpected query structures.
  • Behavioral: Admin accounts accessing or modifying team configurations outside their normal scope or outside business hours; unexpected changes to team configurations or bootstrap package settings not initiated through the Fleet UI.
  • Data: Unexpected presence of sensitive data (password hashes, API tokens) in team configuration fields or bootstrap package content; cross-team configuration changes not attributable to known administrative actions (Fleet Advisory).

Mitigation and workarounds

Fleet has released version 4.81.0 which patches this vulnerability; all users should upgrade immediately (Fleet Advisory). If an immediate upgrade is not possible, the recommended workarounds are to temporarily disable Apple MDM or restrict Team Admin and Global Admin role assignments to only trusted, necessary users. Additionally, organizations should audit existing admin accounts, monitor Fleet API logs for suspicious activity targeting MDM bootstrap package configuration endpoints, and implement additional access controls for administrative API calls until patching is completed (Github Advisory).

Community reactions

The vulnerability was responsibly disclosed by the Secfox Research Team (@secfox-ai), who reported the issue to Fleet's security team (Fleet Advisory). The advisory was published by Fleet maintainer lukeheath on March 27, 2026. The issue was picked up by standard vulnerability tracking feeds including Red Hat CVE database, VulDB, and openSUSE security announcements, but no significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management