
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34391 is a cross-device MDM command disclosure vulnerability in Fleet, an open-source device management platform. Prior to version 4.81.1, a malicious enrolled Windows device can access MDM commands intended for other enrolled devices, potentially exposing sensitive configuration data including WiFi credentials, VPN secrets, and certificate payloads. The vulnerability was published on March 27, 2026, and patched in Fleet version 4.81.1. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.6 (Medium) (GitHub Advisory).
The root cause is classified as CWE-488 (Exposure of Data Element to Wrong Session). When a Windows device reports a specific SyncML status code during MDM communication, Fleet attempts to resend the original command by looking it up in a shared command table. A device-controlled value used in this lookup is not properly validated or scoped to the requesting device, allowing a malicious enrolled device to match and retrieve commands belonging to other enrolled devices. The matched commands are then re-queued to the attacker's device and delivered on the next check-in. Exploitation requires the attacker to control a device already enrolled in Fleet's Windows MDM; the vulnerability does not affect instances where Windows MDM is disabled or where no Windows devices are enrolled (GitHub Advisory).
A malicious enrolled Windows device can intercept MDM commands intended for any other device in the fleet, exposing highly sensitive configuration payloads such as WiFi credentials, VPN secrets, and certificate data across the entire Windows device population managed by the Fleet instance. The impact is limited to confidentiality — there is no integrity or availability impact — but the breadth of exposure is significant, as a single compromised or attacker-controlled device could harvest credentials and secrets from the entire managed fleet. This could facilitate lateral movement or further network compromise if harvested credentials are reused (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-34391. The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the near term. The CVSSv4 exploit maturity is rated "Unreported." Exploitation requires an attacker to already have a device enrolled in the target Fleet Windows MDM environment, which limits the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The issue was responsibly disclosed by researcher @fuzzztf (GitHub Advisory).
Fleet has released version 4.81.1, which patches this vulnerability by properly validating and scoping the device-controlled lookup value used in MDM command retrieval. Organizations unable to upgrade immediately should temporarily disable Windows MDM within their Fleet instance to eliminate the attack surface. For questions or concerns, Fleet's security team can be contacted at security@fleetdm.com or via the #fleet channel in the osquery Slack (GitHub Advisory).
The vulnerability was responsibly disclosed by researcher @fuzzztf and published by Fleet maintainer lukeheath via GitHub Security Advisories on March 27, 2026. No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."