Junglewise Threat Intelligence

CVE-2026-23998: Fleet Device Management authentication bypass in Windows MDM endpoint

CVE-2026-23998 · Severity: high · CVSS 7.5 · Published 2026-05-14

Technologies: github.com/fleetdm/fleet/v4 (Go), Fleet Device Management (fleetdm) Fleet. Vendors: Go.

Executive brief

Fleet is an open-source platform used by IT and security teams to manage and secure fleets of laptops and servers. A security flaw in the Windows device management component could allow an attacker to bypass authentication and impersonate a legitimate Windows computer. If successful, an attacker could steal sensitive configuration data intended for that device, such as Wi-Fi passwords, VPN credentials, and security certificates.

Technical details

A vulnerability exists in Fleet's Windows MDM management endpoint due to improper certificate validation (CWE-295). The endpoint is intended to require mutual TLS (mTLS) for authentication; however, affected versions may incorrectly trust requests that fail to present a valid client certificate. An attacker with knowledge of a specific enrolled device identifier can exploit this to impersonate that device and retrieve its MDM configuration payloads. These payloads often contain sensitive secrets including VPN/Wi-Fi configurations and certificates. The attack requires network access to the MDM endpoint and prior knowledge of a device ID, but does not require valid credentials or user interaction. The issue is fixed in version 4.81.0.

Affected products

  • Fleet Device Management (fleetdm) Fleet < 4.81.0

Timeline

  • 2026-02-20: patched: Version 4.81.0 released
  • 2026-05-13: disclosed: Initial advisory publication
  • 2026-05-14: advisory: GitHub Advisory published/reviewed

References

Related threats