Medium severity4.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103265
CVE-2026-103265
Description
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.