Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package. Version 4.81.1 patches the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package. Version 4.81.1 patches the issue. | |
| Title | Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T19:31:54.764Z
Reserved: 2026-03-27T13:45:29.619Z
Link: CVE-2026-34387
No data.
Status : Received
Published: 2026-03-27T19:16:43.590
Modified: 2026-03-27T19:16:43.590
Link: CVE-2026-34387
No data.
OpenCVE Enrichment
No data.