| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4f9r-x588-pp2h | Fleet's user account creation via invite does not enforce invited email address |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 30 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fleetdm
Fleetdm fleet |
|
| Vendors & Products |
Fleetdm
Fleetdm fleet |
Fri, 27 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token could create an account under an arbitrary email address while inheriting the role granted by the invite, including global admin. Version 4.81.0 patches the issue. | |
| Title | Fleet's user account creation via invite does not enforce invited email address | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T19:01:30.519Z
Reserved: 2026-03-27T13:45:29.619Z
Link: CVE-2026-34389
Updated: 2026-03-30T19:01:26.281Z
Status : Undergoing Analysis
Published: 2026-03-27T20:16:35.957
Modified: 2026-03-30T13:26:29.793
Link: CVE-2026-34389
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:00:47Z
Github GHSA