CVE-2026-101046 | fleetdm Fleet up to 4.88.x cursor-pagination helper /api/v1/fleet/activities appendListOptionsWithCursorToSQL sort sql injection
A vulnerability categorized as critical has been discovered in fleetdm Fleet up to 4.88.x. This impacts the function appendListOptionsWithCursorToSQL of the file /api/v1/fleet/activities of the component cursor-pagination helper. Such manipulation of the argument sort leads to sql injection.
This vulnerability is documented as CVE-2026-101046. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More