CVE-2026-26060
EUVD-2026-1674227.03.2026, 19:16
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fleetdm | fleet | 𝑥 < 4.81.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration