Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet. Version 4.81.1 patches the issue.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-27 20:16
Updated : 2026-03-30 13:26
NVD link : CVE-2026-34391
Mitre link : CVE-2026-34391
CVE.ORG link : CVE-2026-34391
JSON object : View
Products Affected
No product.
CWE
CWE-488
Exposure of Data Element to Wrong Session
