CVE Explorer
CVE-2026-27465
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorized access to Google Calendar resources associated with the service account. Fleet returns configuration data through an API endpoint that is accessible to authenticated users, including those with the lowest-privilege “Observer” role. In affected
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"fleet","vendor":"fleetdm","versions":[{"status":"affected","version":"< 4.80.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b8da976e1c2657edb1d0026efe8cb6e126901a7cf291410dc2b413c818e5f723 · sha256:db59e6e400a8702c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":1.3,"baseSeverity":"LOW","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b8da976e1c2657edb1d0026efe8cb6e126901a7cf291410dc2b413c818e5f723 · sha256:db59e6e400a8702c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-201","description":"CWE-201: Insertion of Sensitive Information Into Sent Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b8da976e1c2657edb1d0026efe8cb6e126901a7cf291410dc2b413c818e5f723 · sha256:db59e6e400a8702c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/fleetdm/fleet/security/advisories/GHSA-2v6m-6xw3-6467","tags":["x_refsource_CONFIRM"],"url":"https://github.com/fleetdm/fleet/security/advisories/GHSA-2v6m-6xw3-6467"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b8da976e1c2657edb1d0026efe8cb6e126901a7cf291410dc2b413c818e5f723 · sha256:db59e6e400a8702c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.