CVE-2026-103265
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Oct 01, 2026
Vendor
unknown
Description
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.