Vulnerability GO-2026-6269
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 25, 2026 at 03:00 PM UTC
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
<4.89.0
<4.89.0
Summary
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
Details
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
1 month ago
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
<4.86.2 GO-2026-6264
<4.86.2 GO-2026-6264
Unknown
1 month ago
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
<4.87.0 GO-2026-6268
<4.87.0 GO-2026-6268
Low Risk
1 month ago
Fleet: ORDER BY column injection on activity list endpoints
<4.89.0 GHSA-rxhg-vcww-2mpw
<4.89.0 GHSA-rxhg-vcww-2mpw
Medium Risk
1 month ago
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
<4.87.0 GHSA-q9c5-pp7m-fm2g
<4.87.0 GHSA-q9c5-pp7m-fm2g
Unknown
1 month ago
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet
<4.87.0 GO-2026-6220
<4.87.0 GO-2026-6220
Impacted packages
Timeline
Published
1 month ago
August 25, 2026 at 03:00 PM UTC
Last Modified
7 hours ago
September 28, 2026 at 03:55 AM UTC