<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:03:30.437764+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359536</id>
    <title>EUVD-2026-359536</title>
    <updated>2026-10-04T17:03:30.496885+00:00</updated>
    <content>EUVD-2026-359536</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48786</id>
    <title>fkie_cve-2026-48786</title>
    <updated>2026-10-04T17:03:30.496921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to low-privilege observer-class users. Other team-facing endpoints mask these fields for observers, but the target search endpoint did not apply the same sanitization, so an authenticated user with the Observer, Observer+, or Technician role, whether global or team-scoped, could retrieve the secrets and agent options by performing a target search against an observer-runnable query. With a leaked team enroll secret an attacker could enroll unauthorized hosts into the affected team, and if the team's agent options contained credentials such as AWS secret access keys or proxy passwords, those values were disclosed as well. This issue is fixed in version 4.87.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-88p2-jj8w-j8qg</id>
    <title>GHSA-88p2-jj8w-j8qg — Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint</title>
    <updated>2026-10-04T17:03:30.496960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/fleetdm/fleet/v4</p>
<p>### Summary</p>
<p>The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not apply the same sanitization.</p>
<p>### Impact</p>
<p>An authenticated user with Observer, Observer+, or Technician role (global or team-scoped) could retrieve unmasked team enroll secrets and team agent options by performing a target search against an observer-runnable query.</p>
<p>With a leaked team enroll secret, an attacker could enroll unauthorized hosts into the affected team. If the team's agent options contained credentials such as AWS secret access keys or proxy passwords, those values were also exposed.</p>
<p>### Patches</p>
<p>- v4.87.0</p>
<p>### Workarounds</p>
<p>If an immediate upgrade is not possible, administrators should:</p>
<p>- Rotate team enroll secrets for any team that may have been exposed
- Rotate any credentials stored in team agent options (AWS keys, proxy passwords, session tokens)
- Restrict Observer and Technician roles to fully trusted users until the patch is applied</p>
<p>### Credits</p>
<p>Fleet thanks @fuzzztf for responsibly reporting this issue.</p>
<p>### For more information</p>
<p>If there are any questions or comments about this advisory:</p>
<p>Send an email to [security@fleetdm.com](mailto:security@fleetdm.com)
Join #fleet in [osquery Slack](https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-88p2-jj8w-j8qg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2788</id>
    <title>WID-SEC-W-2026-2788 — Fleet: Mehrere Schwachstellen</title>
    <updated>2026-10-04T17:03:30.497008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Fleet ausnutzen, um SQL-Injection durchzuführen, beliebigen Code auszuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2788"/>
  </entry>
</feed>
