CVE-2026-23518

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could accept attacker-controlled identity claims, enabling enrollment of unauthorized devices under arbitrary Azure AD user identities. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-01-21 22:15

Updated : 2026-01-26 15:04


NVD link : CVE-2026-23518

Mitre link : CVE-2026-23518

CVE.ORG link : CVE-2026-23518


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature