{"id":"GHSA-x4qr-qw6h-wvxq","summary":"Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint","details":"### Summary\n\nA vulnerability in Fleet's Apple MDM commands listing endpoint allowed authenticated users with the lowest-privilege Observer role to extract sensitive values from joined database tables — including host enrollment secrets and Apple Push Notification Service (APNS) tokens — through a cursor-based binary search oracle. The endpoint accepted a user-supplied `order_key` parameter that was not validated against a column allowlist.\n\n### Impact\n\nThe `GET /api/v1/fleet/mdm/apple/commands` endpoint constructs its query using a deprecated helper that did not restrict which columns could appear in the `ORDER BY` clause. The underlying query joins the `hosts` and `nano_enrollments` tables, so any column on those tables could be supplied as `order_key`. An attacker with Observer credentials could then use the cursor-based pagination parameter (`after`) to binary-search the value of the chosen column one character at a time. The targeted values never appeared in the response body, but the presence or absence of results revealed each character.\n\nWith extracted `node_key` or `orbit_node_key` values, an attacker could impersonate enrolled hosts to Fleet's osquery and Orbit endpoints, submit fabricated host data, and retrieve pending scripts and commands. The APNS values are exploitable only by a party that also possesses the organization's APNS certificate.\n\nExploitation required authenticated Observer access and a Fleet deployment with Apple MDM enabled and at least one queued MDM command. Instances without Apple MDM configured were not affected.\n\n### Workarounds\n\nIf an immediate upgrade is not possible, administrators should:\n\n- Restrict the Observer role to fully trusted users until the patch is applied\n- Rotate `node_key` and `orbit_node_key` for any host suspected of exposure by re-enrolling the affected hosts\n\n### For more information\n\nIf there are any questions or comments about this advisory:\n\nEmail Fleet at [security@fleetdm.com](mailto:security@fleetdm.com)\nJoin #fleet in [osquery Slack](https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEw)\n\n### Credits\n\nFleet thanks the Security Team at Palantir Technologies for responsibly reporting this issue.","aliases":["CVE-2026-46371","GO-2026-5739"],"modified":"2026-06-26T20:20:41Z","published":"2026-06-12T21:00:48Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200","CWE-89"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-12T21:00:48Z"},"references":[{"type":"WEB","url":"https://github.com/fleetdm/fleet/security/advisories/GHSA-x4qr-qw6h-wvxq"},{"type":"PACKAGE","url":"https://github.com/fleetdm/fleet"}],"affected":[{"package":{"name":"github.com/fleetdm/fleet/v4","ecosystem":"Go","purl":"pkg:golang/github.com/fleetdm/fleet/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.84.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.84.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x4qr-qw6h-wvxq/GHSA-x4qr-qw6h-wvxq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}