CVE Explorer
CVE-2026-25963
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. Fleet supports certificate templates that are scoped to individual teams. In affected versions, the batch deletion endpoint validated authorization using a user-supplied team identifier but did not verify that the certificate
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"fleet","vendor":"fleetdm","versions":[{"status":"affected","version":"< 4.80.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4bdf4c4995aaa5d08315750d9c2079bfbfb97ab4db137aed6eb9b073d70dc038 · sha256:4ce09208f8f02fc5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":1.2,"baseSeverity":"LOW","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4bdf4c4995aaa5d08315750d9c2079bfbfb97ab4db137aed6eb9b073d70dc038 · sha256:4ce09208f8f02fc5… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4bdf4c4995aaa5d08315750d9c2079bfbfb97ab4db137aed6eb9b073d70dc038 · sha256:4ce09208f8f02fc5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/fleetdm/fleet/security/advisories/GHSA-5jvp-m9h4-253h","tags":["x_refsource_CONFIRM"],"url":"https://github.com/fleetdm/fleet/security/advisories/GHSA-5jvp-m9h4-253h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4bdf4c4995aaa5d08315750d9c2079bfbfb97ab4db137aed6eb9b073d70dc038 · sha256:4ce09208f8f02fc5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.