HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-26060 — Fleet is open source device management software. Prior to 4.81.0, a vulnerabilit...
Friday, March 27, 2026 at 07:16 PM UTC·Source: NIST NVD
Updated: Thursday, April 2, 2026 at 05:46 PM UTC
Executive Summary
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue.
Analysis
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue.
CVSS Score: 8.8. Published: 2026-03-27T19:16:42.240.