CVE-2026-46370 | fleetdm Fleet up to 4.84.1 Labels Host-Listing Endpoint hosts order_key/after information disclosure
A vulnerability categorized as problematic has been discovered in fleetdm Fleet up to 4.84.1. This affects an unknown function of the file /api/v1/fleet/labels/{id}/hosts of the component Labels Host-Listing Endpoint. Such manipulation of the argument order_key/after leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-46370. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More