
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34386 is a SQL injection vulnerability in Fleet's MDM bootstrap package configuration affecting all versions of the open-source device management software prior to 4.81.0. It allows authenticated users with Team Admin or Global Admin privileges to manipulate database queries via direct API calls, enabling unauthorized modification of team configurations, data exfiltration, and content injection. The vulnerability was published on March 27, 2026, with a patch released in version 4.81.0. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 6.3 (Medium) (Github Advisory, Fleet Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient server-side input validation when processing user-supplied input during MDM bootstrap package configuration (Github Advisory). An attacker can craft malicious input through direct API calls to the MDM bootstrap package configuration endpoint, causing the backend to interpret the input as SQL rather than data, thereby manipulating database queries in unintended ways. Exploitation requires network access, valid Team Admin or Global Admin credentials, and Apple MDM to be enabled on the Fleet instance — instances with Apple MDM disabled are not affected (Fleet Advisory). No public proof-of-concept exploit code has been identified at this time (Github Advisory).
Successful exploitation allows an authenticated attacker to modify arbitrary team configurations beyond their authorized scope, exfiltrate sensitive data from the Fleet database including password hashes and API tokens, inject arbitrary content into team configurations, and potentially escalate privileges (Fleet Advisory). The vulnerability has high impact on confidentiality, integrity, and availability of the Fleet database and team configurations. Cross-team data corruption is also a potential consequence, making this particularly dangerous in multi-tenant Fleet deployments (Github Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of reporting (Github Advisory). The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with elevated privileges (Team Admin or Global Admin), which limits the attacker pool but does not eliminate risk from insider threats or compromised admin accounts (Fleet Advisory).
', --, UNION, SELECT) in configuration fields.Fleet has released version 4.81.0 which patches this vulnerability; all users should upgrade immediately (Fleet Advisory). If an immediate upgrade is not possible, the recommended workarounds are to temporarily disable Apple MDM or restrict Team Admin and Global Admin role assignments to only trusted, necessary users. Additionally, organizations should audit existing admin accounts, monitor Fleet API logs for suspicious activity targeting MDM bootstrap package configuration endpoints, and implement additional access controls for administrative API calls until patching is completed (Github Advisory).
The vulnerability was responsibly disclosed by the Secfox Research Team (@secfox-ai), who reported the issue to Fleet's security team (Fleet Advisory). The advisory was published by Fleet maintainer lukeheath on March 27, 2026. The issue was picked up by standard vulnerability tracking feeds including Red Hat CVE database, VulDB, and openSUSE security announcements, but no significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."