Threat Advisory

Fleet Flaw Exposes Team Enroll Secrets and Credential-Bearing Configuration

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, identified as CVE-2026-48786 with a CVSS score of 6.5, exists in the Fleet target search endpoint where authenticated users with Observer-class roles can view sensitive team information and credential-bearing configuration. This flaw allows an attacker to enroll unauthorized hosts into the affected team if credentials such as AWS secret access keys or proxy passwords are exposed. The issue affects versions prior to 4.87.0 of the github. package, which is used for managing teams and their configurations. An authenticated user with Observer-class roles can retrieve unmasked team enroll secrets and team agent options by performing a target search against an observer-runnable query, leading to potential unauthorized access and data exposure.

RECOMMENDATION:

We recommend you to update Fleet to version 4.87.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, identified as CVE-2026-48786 with a CVSS score of 6.5, exists in the Fleet target search endpoint where authenticated users with Observer-class roles can view sensitive team information and credential-bearing configuration. This flaw allows an attacker to enroll unauthorized hosts into the affected team if credentials such as AWS secret access keys or proxy passwords are exposed. The issue affects versions prior to 4.87.0 of the github. package, which is used for managing teams and their configurations. An authenticated user with Observer-class roles can retrieve unmasked team enroll secrets and team agent options by performing a target search against an observer-runnable query, leading to potential unauthorized access and data exposure.

RECOMMENDATION:

We recommend you to update Fleet to version 4.87.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu