Vulnerability Details CVE-2026-26060
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change. Version 4.81.0 patches the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-26060
-
cpe:2.3:a:fleetdm:fleet:-
-
cpe:2.3:a:fleetdm:fleet:1.0.0
-
cpe:2.3:a:fleetdm:fleet:1.0.1
-
cpe:2.3:a:fleetdm:fleet:1.0.2
-
cpe:2.3:a:fleetdm:fleet:1.0.3
-
cpe:2.3:a:fleetdm:fleet:1.0.4
-
cpe:2.3:a:fleetdm:fleet:1.0.5
-
cpe:2.3:a:fleetdm:fleet:1.0.6
-
cpe:2.3:a:fleetdm:fleet:1.0.7
-
cpe:2.3:a:fleetdm:fleet:1.0.8
-
cpe:2.3:a:fleetdm:fleet:1.0.9
-
cpe:2.3:a:fleetdm:fleet:2.0.0
-
cpe:2.3:a:fleetdm:fleet:2.0.1
-
cpe:2.3:a:fleetdm:fleet:2.0.2
-
cpe:2.3:a:fleetdm:fleet:2.1.0
-
cpe:2.3:a:fleetdm:fleet:2.1.1
-
cpe:2.3:a:fleetdm:fleet:2.1.2
-
cpe:2.3:a:fleetdm:fleet:2.2.0
-
cpe:2.3:a:fleetdm:fleet:2.3.0
-
cpe:2.3:a:fleetdm:fleet:2.4.0
-
cpe:2.3:a:fleetdm:fleet:2.5.0
-
cpe:2.3:a:fleetdm:fleet:2.6.0
-
cpe:2.3:a:fleetdm:fleet:3.0.0
-
cpe:2.3:a:fleetdm:fleet:3.1.0
-
cpe:2.3:a:fleetdm:fleet:3.10.0
-
cpe:2.3:a:fleetdm:fleet:3.10.1
-
cpe:2.3:a:fleetdm:fleet:3.11.0
-
cpe:2.3:a:fleetdm:fleet:3.12.0
-
cpe:2.3:a:fleetdm:fleet:3.13.0
-
cpe:2.3:a:fleetdm:fleet:3.2.0
-
cpe:2.3:a:fleetdm:fleet:3.3.0
-
cpe:2.3:a:fleetdm:fleet:3.4.0
-
cpe:2.3:a:fleetdm:fleet:3.5.0
-
cpe:2.3:a:fleetdm:fleet:3.5.1
-
cpe:2.3:a:fleetdm:fleet:3.6.0
-
cpe:2.3:a:fleetdm:fleet:3.7.0
-
cpe:2.3:a:fleetdm:fleet:3.7.1
-
cpe:2.3:a:fleetdm:fleet:3.7.2
-
cpe:2.3:a:fleetdm:fleet:3.7.3
-
cpe:2.3:a:fleetdm:fleet:3.7.4
-
cpe:2.3:a:fleetdm:fleet:3.8.0
-
cpe:2.3:a:fleetdm:fleet:3.9.0
-
cpe:2.3:a:fleetdm:fleet:4.0.0
-
cpe:2.3:a:fleetdm:fleet:4.0.1
-
cpe:2.3:a:fleetdm:fleet:4.1.0
-
cpe:2.3:a:fleetdm:fleet:4.10.0
-
cpe:2.3:a:fleetdm:fleet:4.11.0
-
cpe:2.3:a:fleetdm:fleet:4.12.0
-
cpe:2.3:a:fleetdm:fleet:4.13.0
-
cpe:2.3:a:fleetdm:fleet:4.13.1
-
cpe:2.3:a:fleetdm:fleet:4.13.2
-
cpe:2.3:a:fleetdm:fleet:4.14.0
-
cpe:2.3:a:fleetdm:fleet:4.15.0
-
cpe:2.3:a:fleetdm:fleet:4.16.0
-
cpe:2.3:a:fleetdm:fleet:4.17.0
-
cpe:2.3:a:fleetdm:fleet:4.17.1
-
cpe:2.3:a:fleetdm:fleet:4.18.0
-
cpe:2.3:a:fleetdm:fleet:4.19.0
-
cpe:2.3:a:fleetdm:fleet:4.19.1
-
cpe:2.3:a:fleetdm:fleet:4.2.0
-
cpe:2.3:a:fleetdm:fleet:4.2.1
-
cpe:2.3:a:fleetdm:fleet:4.2.2
-
cpe:2.3:a:fleetdm:fleet:4.2.3
-
cpe:2.3:a:fleetdm:fleet:4.2.4
-
cpe:2.3:a:fleetdm:fleet:4.20.0
-
cpe:2.3:a:fleetdm:fleet:4.20.1
-
cpe:2.3:a:fleetdm:fleet:4.21.0
-
cpe:2.3:a:fleetdm:fleet:4.22.0
-
cpe:2.3:a:fleetdm:fleet:4.22.1
-
cpe:2.3:a:fleetdm:fleet:4.23.0
-
cpe:2.3:a:fleetdm:fleet:4.24.0
-
cpe:2.3:a:fleetdm:fleet:4.24.1
-
cpe:2.3:a:fleetdm:fleet:4.25.0
-
cpe:2.3:a:fleetdm:fleet:4.26.0
-
cpe:2.3:a:fleetdm:fleet:4.27.0
-
cpe:2.3:a:fleetdm:fleet:4.27.1
-
cpe:2.3:a:fleetdm:fleet:4.28.0
-
cpe:2.3:a:fleetdm:fleet:4.28.1
-
cpe:2.3:a:fleetdm:fleet:4.29.0
-
cpe:2.3:a:fleetdm:fleet:4.29.1
-
cpe:2.3:a:fleetdm:fleet:4.3.0
-
cpe:2.3:a:fleetdm:fleet:4.3.1
-
cpe:2.3:a:fleetdm:fleet:4.3.2
-
cpe:2.3:a:fleetdm:fleet:4.30.0
-
cpe:2.3:a:fleetdm:fleet:4.30.1
-
cpe:2.3:a:fleetdm:fleet:4.31.0
-
cpe:2.3:a:fleetdm:fleet:4.31.1
-
cpe:2.3:a:fleetdm:fleet:4.32.0
-
cpe:2.3:a:fleetdm:fleet:4.33.0
-
cpe:2.3:a:fleetdm:fleet:4.33.1
-
cpe:2.3:a:fleetdm:fleet:4.34.0
-
cpe:2.3:a:fleetdm:fleet:4.34.1
-
cpe:2.3:a:fleetdm:fleet:4.35.0
-
cpe:2.3:a:fleetdm:fleet:4.35.1
-
cpe:2.3:a:fleetdm:fleet:4.35.2
-
cpe:2.3:a:fleetdm:fleet:4.36.0
-
cpe:2.3:a:fleetdm:fleet:4.37.0
-
cpe:2.3:a:fleetdm:fleet:4.38.0
-
cpe:2.3:a:fleetdm:fleet:4.38.1
-
cpe:2.3:a:fleetdm:fleet:4.39.0
-
cpe:2.3:a:fleetdm:fleet:4.4.0
-
cpe:2.3:a:fleetdm:fleet:4.4.1
-
cpe:2.3:a:fleetdm:fleet:4.4.2
-
cpe:2.3:a:fleetdm:fleet:4.4.3
-
cpe:2.3:a:fleetdm:fleet:4.40.0
-
cpe:2.3:a:fleetdm:fleet:4.41.0
-
cpe:2.3:a:fleetdm:fleet:4.41.1
-
cpe:2.3:a:fleetdm:fleet:4.42.0
-
cpe:2.3:a:fleetdm:fleet:4.43.0
-
cpe:2.3:a:fleetdm:fleet:4.43.1
-
cpe:2.3:a:fleetdm:fleet:4.43.2
-
cpe:2.3:a:fleetdm:fleet:4.43.3
-
cpe:2.3:a:fleetdm:fleet:4.44.0
-
cpe:2.3:a:fleetdm:fleet:4.44.1
-
cpe:2.3:a:fleetdm:fleet:4.45.0
-
cpe:2.3:a:fleetdm:fleet:4.45.1
-
cpe:2.3:a:fleetdm:fleet:4.46.0
-
cpe:2.3:a:fleetdm:fleet:4.46.1
-
cpe:2.3:a:fleetdm:fleet:4.46.2
-
cpe:2.3:a:fleetdm:fleet:4.47.0
-
cpe:2.3:a:fleetdm:fleet:4.47.1
-
cpe:2.3:a:fleetdm:fleet:4.47.2
-
cpe:2.3:a:fleetdm:fleet:4.47.3
-
cpe:2.3:a:fleetdm:fleet:4.48.0
-
cpe:2.3:a:fleetdm:fleet:4.48.1
-
cpe:2.3:a:fleetdm:fleet:4.48.2
-
cpe:2.3:a:fleetdm:fleet:4.48.3
-
cpe:2.3:a:fleetdm:fleet:4.49.0
-
cpe:2.3:a:fleetdm:fleet:4.49.1
-
cpe:2.3:a:fleetdm:fleet:4.49.2
-
cpe:2.3:a:fleetdm:fleet:4.49.3
-
cpe:2.3:a:fleetdm:fleet:4.49.4
-
cpe:2.3:a:fleetdm:fleet:4.5.0
-
cpe:2.3:a:fleetdm:fleet:4.5.1
-
cpe:2.3:a:fleetdm:fleet:4.50.0
-
cpe:2.3:a:fleetdm:fleet:4.50.1
-
cpe:2.3:a:fleetdm:fleet:4.50.2
-
cpe:2.3:a:fleetdm:fleet:4.51.0
-
cpe:2.3:a:fleetdm:fleet:4.51.1
-
cpe:2.3:a:fleetdm:fleet:4.52.0
-
cpe:2.3:a:fleetdm:fleet:4.53.0
-
cpe:2.3:a:fleetdm:fleet:4.53.1
-
cpe:2.3:a:fleetdm:fleet:4.53.2
-
cpe:2.3:a:fleetdm:fleet:4.53.3
-
cpe:2.3:a:fleetdm:fleet:4.54.0
-
cpe:2.3:a:fleetdm:fleet:4.54.1
-
cpe:2.3:a:fleetdm:fleet:4.54.2
-
cpe:2.3:a:fleetdm:fleet:4.55.0
-
cpe:2.3:a:fleetdm:fleet:4.55.1
-
cpe:2.3:a:fleetdm:fleet:4.55.2
-
cpe:2.3:a:fleetdm:fleet:4.56.0
-
cpe:2.3:a:fleetdm:fleet:4.57.0
-
cpe:2.3:a:fleetdm:fleet:4.57.1
-
cpe:2.3:a:fleetdm:fleet:4.57.2
-
cpe:2.3:a:fleetdm:fleet:4.57.3
-
cpe:2.3:a:fleetdm:fleet:4.58.0
-
cpe:2.3:a:fleetdm:fleet:4.58.1
-
cpe:2.3:a:fleetdm:fleet:4.59.0
-
cpe:2.3:a:fleetdm:fleet:4.59.1
-
cpe:2.3:a:fleetdm:fleet:4.6.0
-
cpe:2.3:a:fleetdm:fleet:4.6.1
-
cpe:2.3:a:fleetdm:fleet:4.6.2
-
cpe:2.3:a:fleetdm:fleet:4.60.0
-
cpe:2.3:a:fleetdm:fleet:4.60.1
-
cpe:2.3:a:fleetdm:fleet:4.61.0
-
cpe:2.3:a:fleetdm:fleet:4.62.0
-
cpe:2.3:a:fleetdm:fleet:4.62.1
-
cpe:2.3:a:fleetdm:fleet:4.62.2
-
cpe:2.3:a:fleetdm:fleet:4.62.3
-
cpe:2.3:a:fleetdm:fleet:4.62.4
-
cpe:2.3:a:fleetdm:fleet:4.63.0
-
cpe:2.3:a:fleetdm:fleet:4.63.1
-
cpe:2.3:a:fleetdm:fleet:4.63.2
-
cpe:2.3:a:fleetdm:fleet:4.64.0
-
cpe:2.3:a:fleetdm:fleet:4.64.1
-
cpe:2.3:a:fleetdm:fleet:4.64.2
-
cpe:2.3:a:fleetdm:fleet:4.65.0
-
cpe:2.3:a:fleetdm:fleet:4.66.0
-
cpe:2.3:a:fleetdm:fleet:4.67.0
-
cpe:2.3:a:fleetdm:fleet:4.67.1
-
cpe:2.3:a:fleetdm:fleet:4.67.2
-
cpe:2.3:a:fleetdm:fleet:4.67.3
-
cpe:2.3:a:fleetdm:fleet:4.68.0
-
cpe:2.3:a:fleetdm:fleet:4.68.1
-
cpe:2.3:a:fleetdm:fleet:4.69.0
-
cpe:2.3:a:fleetdm:fleet:4.7.0
-
cpe:2.3:a:fleetdm:fleet:4.70.0
-
cpe:2.3:a:fleetdm:fleet:4.70.1
-
cpe:2.3:a:fleetdm:fleet:4.71.0
-
cpe:2.3:a:fleetdm:fleet:4.71.1
-
cpe:2.3:a:fleetdm:fleet:4.72.0
-
cpe:2.3:a:fleetdm:fleet:4.72.1
-
cpe:2.3:a:fleetdm:fleet:4.73.0
-
cpe:2.3:a:fleetdm:fleet:4.73.1
-
cpe:2.3:a:fleetdm:fleet:4.73.2
-
cpe:2.3:a:fleetdm:fleet:4.73.3
-
cpe:2.3:a:fleetdm:fleet:4.73.4
-
cpe:2.3:a:fleetdm:fleet:4.73.5
-
cpe:2.3:a:fleetdm:fleet:4.74.0
-
cpe:2.3:a:fleetdm:fleet:4.75.0
-
cpe:2.3:a:fleetdm:fleet:4.75.1
-
cpe:2.3:a:fleetdm:fleet:4.75.2
-
cpe:2.3:a:fleetdm:fleet:4.76.0
-
cpe:2.3:a:fleetdm:fleet:4.76.1
-
cpe:2.3:a:fleetdm:fleet:4.76.2
-
cpe:2.3:a:fleetdm:fleet:4.77.0
-
cpe:2.3:a:fleetdm:fleet:4.77.1
-
cpe:2.3:a:fleetdm:fleet:4.78.0
-
cpe:2.3:a:fleetdm:fleet:4.78.1
-
cpe:2.3:a:fleetdm:fleet:4.78.2
-
cpe:2.3:a:fleetdm:fleet:4.78.3
-
cpe:2.3:a:fleetdm:fleet:4.79.0
-
cpe:2.3:a:fleetdm:fleet:4.79.1
-
cpe:2.3:a:fleetdm:fleet:4.8.0
-
cpe:2.3:a:fleetdm:fleet:4.80.0
-
cpe:2.3:a:fleetdm:fleet:4.80.1
-
cpe:2.3:a:fleetdm:fleet:4.80.2
-
cpe:2.3:a:fleetdm:fleet:4.80.3
-
cpe:2.3:a:fleetdm:fleet:4.9.0
-
cpe:2.3:a:fleetdm:fleet:4.9.1