CVE-2026-34391: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-34391 is a cross-device MDM command disclosure vulnerability in Fleet, an open-source device management platform. Prior to version 4.81.1, a malicious enrolled Windows device can access MDM commands intended for other enrolled devices, potentially exposing sensitive configuration data including WiFi credentials, VPN secrets, and certificate payloads. The vulnerability was published on March 27, 2026, and patched in Fleet version 4.81.1. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.6 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-488 (Exposure of Data Element to Wrong Session). When a Windows device reports a specific SyncML status code during MDM communication, Fleet attempts to resend the original command by looking it up in a shared command table. A device-controlled value used in this lookup is not properly validated or scoped to the requesting device, allowing a malicious enrolled device to match and retrieve commands belonging to other enrolled devices. The matched commands are then re-queued to the attacker's device and delivered on the next check-in. Exploitation requires the attacker to control a device already enrolled in Fleet's Windows MDM; the vulnerability does not affect instances where Windows MDM is disabled or where no Windows devices are enrolled (GitHub Advisory).

Impact

A malicious enrolled Windows device can intercept MDM commands intended for any other device in the fleet, exposing highly sensitive configuration payloads such as WiFi credentials, VPN secrets, and certificate data across the entire Windows device population managed by the Fleet instance. The impact is limited to confidentiality — there is no integrity or availability impact — but the breadth of exposure is significant, as a single compromised or attacker-controlled device could harvest credentials and secrets from the entire managed fleet. This could facilitate lateral movement or further network compromise if harvested credentials are reused (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-34391. The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the near term. The CVSSv4 exploit maturity is rated "Unreported." Exploitation requires an attacker to already have a device enrolled in the target Fleet Windows MDM environment, which limits the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The issue was responsibly disclosed by researcher @fuzzztf (GitHub Advisory).

Exploitation steps

  1. Enroll a malicious device: Enroll an attacker-controlled Windows device into the target Fleet Windows MDM environment.
  2. Trigger SyncML status code: During MDM communication, send a specific SyncML status code that causes Fleet to attempt to resend an original command by querying the shared command table.
  3. Manipulate the lookup value: Craft the device-controlled value used in the command lookup to reference command identifiers belonging to other enrolled devices rather than the attacker's own device.
  4. Receive cross-device commands: On the next MDM check-in, Fleet re-queues and delivers the matched commands (intended for other devices) to the attacker's device, exposing their payloads — including WiFi credentials, VPN secrets, and certificate data.
  5. Harvest sensitive data: Extract the sensitive configuration data from the received MDM commands for use in further attacks such as unauthorized network access or lateral movement (GitHub Advisory).

Indicators of compromise

  • Logs: Fleet server logs showing a single device receiving an unusually high volume of MDM commands, or commands associated with device identifiers other than the requesting device's own identifier.
  • Logs: Repeated SyncML status codes from a single device that trigger command re-queue operations in Fleet's MDM processing pipeline.
  • Network: MDM check-in requests from a device that result in delivery of configuration payloads (WiFi profiles, VPN configs, certificates) not originally targeted at that device.
  • Application: Fleet audit logs showing MDM commands for multiple device targets being delivered to a single enrolled device across successive check-ins (GitHub Advisory).

Mitigation and workarounds

Fleet has released version 4.81.1, which patches this vulnerability by properly validating and scoping the device-controlled lookup value used in MDM command retrieval. Organizations unable to upgrade immediately should temporarily disable Windows MDM within their Fleet instance to eliminate the attack surface. For questions or concerns, Fleet's security team can be contacted at security@fleetdm.com or via the #fleet channel in the osquery Slack (GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by researcher @fuzzztf and published by Fleet maintainer lukeheath via GitHub Security Advisories on March 27, 2026. No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified at this time (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management