📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 22m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h Global vulnerability Artificial Intelligence and Technology HIGH 22m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h Global vulnerability Artificial Intelligence and Technology HIGH 22m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h
Vulnerabilities

CVE-2026-34391

High
Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other
CWE-488 — Weakness Type
Published: Mar 27, 2026  ·  Modified: Apr 3, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet. Version 4.81.1 patches the issue.

🤖 AI Executive Summary

Fleet versions prior to 4.81.1 contain a Windows MDM command processing vulnerability allowing malicious enrolled devices to access commands intended for other devices, exposing sensitive data like WiFi credentials and VPN secrets. This cross-device access vulnerability affects the entire Windows fleet managed through Fleet.

📄 Description (Arabic)

تسمح الثغرة للأجهزة المسجلة الخبيثة بتجاوز ضوابط التحكم في الوصول والوصول إلى أوامر MDM المخصصة لأجهزة أخرى في البيئة. يمكن للمهاجمين استخراج بيانات حساسة مثل بيانات اعتماد WiFi وأسرار VPN وحمولات الشهادات من الأجهزة الأخرى. تؤثر هذه الثغرة على جميع أجهزة Windows المدارة عبر Fleet قبل الإصدار 4.81.1.

🤖 ملخص تنفيذي (AI)

إصدارات Fleet السابقة للإصدار 4.81.1 تحتوي على ثغرة في معالجة أوامر Windows MDM تسمح للأجهزة المسجلة الخبيثة بالوصول إلى الأوامر المخصصة لأجهزة أخرى، مما يعرض البيانات الحساسة مثل بيانات اعتماد WiFi وأسرار VPN. تؤثر هذه الثغرة على جميع أجهزة Windows المدارة عبر Fleet.

🤖 AI Intelligence Analysis Analyzed: May 2, 2026 23:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
government telecom banking healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
7.0
/ 10.0
🔧 Remediation Steps (English)
Immediately upgrade Fleet to version 4.81.1 or later. Review access logs for unauthorized MDM command access. Rotate all exposed credentials including WiFi passwords, VPN secrets, and certificates. Implement network segmentation to limit device-to-device communication. Enable enhanced monitoring of MDM command processing.
🔧 خطوات المعالجة (العربية)
قم بترقية Fleet إلى الإصدار 4.81.1 أو أحدث فوراً. راجع سجلات الوصول للكشف عن الوصول غير المصرح به لأوامر MDM. قم بتدوير جميع بيانات الاعتماد المكشوفة بما في ذلك كلمات مرور WiFi وأسرار VPN والشهادات. طبق تقسيم الشبكة لتحديد الاتصالات بين الأجهزة. فعّل المراقبة المحسّنة لمعالجة أوامر MDM.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.2 5.2.1 5.3.1
🔵 SAMA CSF
AC-3 AC-6 SI-4
🟡 ISO 27001:2022
A.9.2.1 A.9.2.5 A.12.4.1
📦 Affected Products / CPE 1 entries
fleetdm:fleet
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-488
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-03-27
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-488
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.