CVE-2026-34389

MEDIUM

Fleet's user account creation via invite does not enforce invited email address

Title source: cna
STIX 2.1

Description

Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token could create an account under an arbitrary email address while inheriting the role granted by the invite, including global admin. Version 4.81.0 patches the issue.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (3)
fleetdm/fleet < 4.81.1
fleetdm/fleet 0 - 4.81.0Go
fleetdm/fleet < 4.81.0
Published Mar 27, 2026
Tracked Since Mar 29, 2026