CVE-2026-23518

Source
https://cve.org/CVERecord?id=CVE-2026-23518
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23518.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23518
Aliases
Published
2026-01-21T21:50:47.998Z
Modified
2026-02-03T22:41:11.727434Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Details

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could accept attacker-controlled identity claims, enabling enrollment of unauthorized devices under arbitrary Azure AD user identities. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23518.json",
    "cwe_ids": [
        "CWE-347"
    ]
}
References

Affected packages

Git / github.com/fleetdm/fleet

Affected ranges

Type
GIT
Repo
https://github.com/fleetdm/fleet
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.78.0"
        },
        {
            "fixed": "4.78.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/fleetdm/fleet
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.77.0"
        },
        {
            "fixed": "4.77.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/fleetdm/fleet
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.76.0"
        },
        {
            "fixed": "4.76.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/fleetdm/fleet
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.75.0"
        },
        {
            "fixed": "4.75.2"
        }
    ]
}

Affected versions

fleet-v4.*
fleet-v4.75.0
fleet-v4.75.1
fleet-v4.76.0
fleet-v4.76.1
fleet-v4.77.0
fleet-v4.78.0
fleet-v4.78.1
fleet-v4.78.2
v4.*
v4.75.0
v4.76.0
v4.77.0
v4.78.0
v4.78.1
v4.78.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23518.json"