CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-48786

highCVSS 6.5covered by 2 sourcesfirst seen 2026-08-12
An attacker can exploit multiple vulnerabilities in Fleet to conduct SQL injection, execute arbitrary code, manipulate data, or disclose confidential information.

CSIRTS triage

What
Multiple vulnerabilities in Fleet enable SQL injection, arbitrary code execution, data manipulation, and information disclosure.
Who is affected
Fleet deployments exposed to network attacks or used with untrusted input.
Urgency
High urgency; high severity combines multiple critical attack vectors.
Action
Update Fleet to a patched version addressing CVE-2026-48786 and CVE-2026-54245.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-48786

Get an email if CVE-2026-48786 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-48786

CVE.org record

Embed the live status

CVE-2026-48786 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-48786 status](https://www.csirts.com/badge/CVE-2026-48786)](https://www.csirts.com/cve/CVE-2026-48786)