<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:22:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-221181</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221181</link>
      <description>EUVD-2026-221181</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221181</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27509</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27509</link>
      <description>&lt;p&gt;fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to forged assertions if f MDM enrollment is enabled. This vulnerability is fixed in 4.64.2, 4.63.2, 4.62.4, and 4.58.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to forged assertions if f MDM enrollment is enabled. This vulnerability is fixed in 4.64.2, 4.63.2, 4.62.4, and 4.58.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27509</guid>
    </item>
    <item>
      <title>GHSA-52jx-g6m5-h735 — Fleet has SAML authentication vulnerability due to improper SAML response validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-52jx-g6m5-h735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/fleetdm/fleet/v4&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in Fleet’s SAML authentication handling could allow an attacker to forge authentication assertions and gain unauthorized access to Fleet. In certain configurations, this could result in the creation of new user accounts, including administrative accounts. This issue affects Fleet deployments using single sign-on (SSO).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to:&lt;/p&gt;
&lt;p&gt;- Forge authentication assertions, potentially impersonating legitimate users.
- If Just-In-Time (JIT) provisioning is enabled, the attacker could provision a new administrative user account.
- If MDM enrollment is enabled, certain endpoints could be used to create new accounts tied to forged assertions.&lt;/p&gt;
&lt;p&gt;This could allow unauthorized access to Fleet, including administrative access, visibility into device data, and modification of configuration.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue is addressed in commit [fc96cc4](https://github.com/fleetdm/fleet/commit/fc96cc4e91047250afb12f65ad70e90b30a7fb1c) and is available in Fleet version 4.64.2.&lt;/p&gt;
&lt;p&gt;The following backport versions also address this issue:&lt;/p&gt;
&lt;p&gt;- 4.63.2
- 4.62.4
- 4.58.1
- 4.53.2&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If an immediate upgrade is not possible, Fleet users should temporarily disable [single-sign-on (SSO)](https://fleetdm.com/docs/deploy/single-sign-on-sso) and use password authentication.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Thank you @hakivvi, as well as Jeffrey Hofmann and Colby Morgan from the Robinhood Red Team…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/fleetdm/fleet/v4&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in Fleet’s SAML authentication handling could allow an attacker to forge authentication assertions and gain unauthorized access to Fleet. In certain configurations, this could result in the creation of new user accounts, including administrative accounts. This issue affects Fleet deployments using single sign-on (SSO).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to:&lt;/p&gt;
&lt;p&gt;- Forge authentication assertions, potentially impersonating legitimate users.
- If Just-In-Time (JIT) provisioning is enabled, the attacker could provision a new administrative user account.
- If MDM enrollment is enabled, certain endpoints could be used to create new accounts tied to forged assertions.&lt;/p&gt;
&lt;p&gt;This could allow unauthorized access to Fleet, including administrative access, visibility into device data, and modification of configuration.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue is addressed in commit [fc96cc4](https://github.com/fleetdm/fleet/commit/fc96cc4e91047250afb12f65ad70e90b30a7fb1c) and is available in Fleet version 4.64.2.&lt;/p&gt;
&lt;p&gt;The following backport versions also address this issue:&lt;/p&gt;
&lt;p&gt;- 4.63.2
- 4.62.4
- 4.58.1
- 4.53.2&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If an immediate upgrade is not possible, Fleet users should temporarily disable [single-sign-on (SSO)](https://fleetdm.com/docs/deploy/single-sign-on-sso) and use password authentication.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Thank you @hakivvi, as well as Jeffrey Hofmann and Colby Morgan from the Robinhood Red Team…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-52jx-g6m5-h735</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14889-1 — govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0522 — Fleet: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0522</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Fleet ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Fleet ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0522</guid>
    </item>
  </channel>
</rss>
