CVE-2026-24004
Last modified
CVE-2026-24004 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal of individual Android devices from Fleet management. If Android MDM is enabled, an attacker could send a crafted request to the Android Pub/Sub endpoint to unenroll a targeted Android device from Fleet without authentication. This issue does not grant access to Fleet, allow execution of commands, or provide visibility into device data. Impact is limited to disruption of Android device management for the affected device. Version 4.80.1 fixes the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Android MDM.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fleetdm | Fleet | < 4.80.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-24004?
How severe is CVE-2026-24004?
How do I fix CVE-2026-24004?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23999Fleet is open source device management software. In versions…5.5
- CVE-2026-2400CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Inje…4.3
- CVE-2026-24000Fleet is open source device management software. Prior to ve…5.3
- CVE-2026-24001jsdiff is a JavaScript text differencing implementation. Pri…7.5
- CVE-2026-24002Grist is spreadsheet software using Python as its formula la…9.6
- CVE-2026-24003EVerest is an EV charging software stack. In versions up to …5.3
- CVE-2026-24005Kruise provides automated management of large-scale applicat…7.6
- CVE-2026-24006Seroval facilitates JS value stringification, including comp…7.5
- CVE-2026-24007Tuleap is an Open Source Suite for management of software de…4.6
- CVE-2026-24009Docling Core (or docling-core) is a library that defines cor…9.8
- CVE-2026-2401CWE-532 Insertion of Sensitive Information into Log File vul…5
- CVE-2026-24010Horilla is a free and open source Human Resource Management …8
Are you affected by CVE-2026-24004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
