SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-54245

HIGH · CVSS 7.6 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Fleet open-source device management platform is vulnerable to SQL injection in versions prior to 4.86.2, specifically within the Okta conditional access integration. An attacker controlling a single enrolled host can exploit this vulnerability to read or modify arbitrary data in the Fleet database, potentially extracting session tokens to gain global administrator access, which could lead to remote code execution on managed hosts. Organizations using Fleet Premium with the Okta integration should prioritize upgrading to version 4.86.2 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54245
Severity
HIGH
CVSS
7.6
EPSS
0.34%

Original NVD Description

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a database query without proper parameterization, allowing an attacker who controls a single enrolled host to read or modify arbitrary data in the Fleet database. The value is reported by the host's own agent and stored verbatim, then used on an unauthenticated request path that supports the conditional access integration, so any party controlling one enrolled host, the lowest-privilege position in the product, can influence the query. By disclosing arbitrary database contents an attacker can extract stored session tokens and replay them to act as a global administrator, and on a managed fleet that administrator access enables running scripts on enrolled hosts, leading to remote code execution. The issue requires Fleet Premium with the Okta conditional access integration enabled and does not affect instances where it is not configured. This issue is fixed in version 4.86.2.