Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token could create an account under an arbitrary email address while inheriting the role granted by the invite, including global admin.
If an attacker gains access to a valid invite token, they can create a Fleet user account with an email address of their choosing while inheriting the inviteās assigned role and team memberships.
This issue:
If upgrading immediately is not possible:
If there are any questions or comments about this advisory:
Send an email to security@fleetdm.com
Fleet thanks @fuzzztf for responsibly reporting this issue.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-287"
],
"nvd_published_at": "2026-03-27T20:16:35Z",
"github_reviewed_at": "2026-03-30T19:29:13Z",
"severity": "MODERATE"
}