HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-26060 — Fleet is open source device management software. Prior to 4.81.0, a vulnerabilit...

Friday, March 27, 2026 at 07:16 PM UTC·Source: NIST NVD

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue.

Analysis

Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue. CVSS Score: 8.8. Published: 2026-03-27T19:16:42.240.

Indicators of Compromise (1)

CVE (1)
CVE-2026-26060
Source Attribution

Originally published by NIST NVD on Mar 27, 2026. Verified by: NIST.

Related Threats